Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-12 Thread Pascal Quantin
Hi, Le 12 août 2015 6:21 PM, "Bill Meier" a écrit : > > [Resend] > > I see that several people (Anders, ...) been building with MSVC-2015 (VC14) and have fixed a number of issues. > > So: I decided to download VC14 and give it a try (using NMake). > > A few questions: > > Are you using CMake or NM

Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-12 Thread Pascal Quantin
Le 12 août 2015 7:19 PM, "Graham Bloice" a écrit : > > On 12 August 2015 at 17:57, Pascal Quantin wrote: >> >> Hi, >> >> Le 12 août 2015 6:21 PM, "Bill Meier" a écrit : >> > >> > [Resend] >> > >> > I see

Re: [Wireshark-dev] removing mergecap -T option

2015-08-14 Thread Pascal Quantin
Le 14 août 2015 6:18 PM, "Hadriel Kaplan" a écrit : > > Howdy, > Due to some reported bugs and inconsistencies, I'm refactoring the > capture file merging code in mergecap.c and file.c's cf_merge_files() > - basically gutting them and putting most of the logic into a common > "merge_files()" funct

Re: [Wireshark-dev] removing mergecap -T option

2015-08-14 Thread Pascal Quantin
Le 14 août 2015 6:30 PM, "Hadriel Kaplan" a écrit : > > But isn't that the purpose of editcap? I'm only talking about > removing it from mergecap. Mmm, sorry I did not realize that. No specific objection on my side then. Pascal. > > -hadriel > >

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-15 Thread Pascal Quantin
Hi Yang, 2015-08-15 14:38 GMT+02:00 Yang Luo : > Hi list, > > Thanks for your tests for the first 3 versions of Npcap, with your tests I > am able to release Npcap 0.04 version as below: > 1) Fixed the BAD_POOL_CALLER BSoD. > 2) Updated Packet, NPFInstall, NPcapHelper projects to MSVC 2010, updat

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-16 Thread Pascal Quantin
Le 16 août 2015 3:39 PM, "Pascal Quantin" a écrit : > > Hi Yang, > > 2015-08-16 14:18 GMT+02:00 Yang Luo : >> >> Hi Pascal, >> >> I think this BSoD is caused by the Winsock Kernel init code in Npcap driver (NPF_WSKStartup call or NPF_WSKInitSockets c

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-18 Thread Pascal Quantin
Le 18 août 2015 5:04 PM, "Yang Luo" a écrit : > > Hi Pascal, > > I have analyzed your log and it shows that WSK_CLIENT_DISPATCH::WskSocket function fails with STATUS_ACCESS_DENIED. The result turns out to be a bug: If you launch Wireshark with no Admin right, the WSK code fails to init, so Npcap

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-18 Thread Pascal Quantin
Hi Yang, like Jim, I confirm that this version is working fine both on my Windows 10 guest and host OS. Cheers, Pascal. 2015-08-18 18:22 GMT+02:00 Jim Young : > Hello Yang, > > > With Npcap 0.04-r3 the Npcap Loopback Adapter is again visible and usable > as a sniffable interface to Wireshark. [

Re: [Wireshark-dev] Windows file wildcard support

2015-08-20 Thread Pascal Quantin
2015-08-20 14:38 GMT+02:00 Anders Broman : > Hi, > I don't build with CMAKE currently so I can't test but it might still be a > problem with setargv > We get this warning on the buildboot: > > LINK : warning LNK4044: unrecognized option '/RELEASE;setargv.obj'; > ignored > [C:\buildbot\wireshark\wi

Re: [Wireshark-dev] Question about changing Npcap loopback interface's MTU to 65536

2015-08-21 Thread Pascal Quantin
Hi Yang, 2015-08-21 14:46 GMT+02:00 Yang Luo : > Hi list, > > I have updated Npcap to 0.04-r4. This version modified "Npcap Loopback > Adapter"'s MTU to 65536, so the maximum packet size is 65550 (65536 + > eth_hdr_size). > > But I found weird result in Wireshark's "Interface Details" dialog. > >

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-22 Thread Pascal Quantin
2015-08-22 7:55 GMT+02:00 Yang Luo : > Hi list, > > Npcap 0.04 r5 has added the DLT_NULL protocol support, you need to check > the *"Use DLT_NULL protocol as loopback packets' link layer instead of > Ethernet II"* option when installing (default is not checked). The > problem is Wireshark didn't r

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
2015-08-24 3:38 GMT+02:00 Yang Luo : > Hi list, > > In latest 0.04 r6 version, I have used 0x02, 0x00, 0x00, 0x00 for an IPv4 > packet and 0x18, 0x00, 0x00, 0x00 for an IPv6 packet (tell me if you have > better value for IPv6). The driver can return NdisMediumNull now for > loopback interface. Wir

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
2015-08-24 10:19 GMT+02:00 Pascal Quantin : > 2015-08-24 3:38 GMT+02:00 Yang Luo : > >> Hi list, >> >> In latest 0.04 r6 version, I have used 0x02, 0x00, 0x00, 0x00 for an >> IPv4 packet and 0x18, 0x00, 0x00, 0x00 for an IPv6 packet (tell me if >> you have be

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
2015-08-24 10:28 GMT+02:00 Guy Harris : > > On Aug 24, 2015, at 1:19 AM, Pascal Quantin > wrote: > > > any reason for not using NdisMediumLoopback that is defined since Vista > according to > https://msdn.microsoft.com/en-us/library/windows/hardware/ff565910%28v=vs.85%29

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
2015-08-24 10:29 GMT+02:00 Pascal Quantin : > > > 2015-08-24 10:19 GMT+02:00 Pascal Quantin : > >> 2015-08-24 3:38 GMT+02:00 Yang Luo : >> >>> Hi list, >>> >>> In latest 0.04 r6 version, I have used 0x02, 0x00, 0x00, 0x00 for an >>> IPv

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
ot;. > Media is the plural form of medium. "media supported" could list several medium, while only one can be in use at a given time. So the current wording seems OK to me. Note that I updated the list of enum (so as to support loopback value) in https://code.wireshark.org/revi

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
Le 24 août 2015 12:19 PM, "Yang Luo" a écrit : > > Hi Pascal, > > On Mon, Aug 24, 2015 at 4:19 PM, Pascal Quantin wrote: >> >> >> >> Hi Yang, >> >> any reason for not using NdisMediumLoopback that is defined since Vista according to

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
2015-08-24 12:30 GMT+02:00 Yang Luo : > Hi Pascal, > > On Mon, Aug 24, 2015 at 5:46 PM, Pascal Quantin > wrote: > >> >> >>> I personally think data returned by OID_GEN_MEDIA_IN_USE should be >>> identical with the one returned by OID_GEN_MEDIA_SUPP

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-08-24 Thread Pascal Quantin
"Custom linktype: NDIS doesn't > provide an equivalent". And it seems that Npcap loopback adapter will > continue to use the "NdisMediumNull - DLT_NULL" pair for now. > Thanks for the link Yang, I was not aware of those defines. I also added them to the patch. Pascal

Re: [Wireshark-dev] Improve the loopback wiki page

2015-08-27 Thread Pascal Quantin
Le 25 août 2015 3:41 PM, "Yang Luo" a écrit : > > Hi list, > > I noticed that "Loopback capture setup" ( https://wiki.wireshark.org/CaptureSetup/Loopback) has some discussions about loopback capturing on Windows, and it is not updated these months. As Npcap can capture and send loopback traffic no

Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-29 Thread Pascal Quantin
Hi all, 2015-08-12 18:57 GMT+02:00 Pascal Quantin : > Hi, > Le 12 août 2015 6:21 PM, "Bill Meier" a écrit : > > > > [Resend] > > > > I see that several people (Anders, ...) been building with MSVC-2015 > (VC14) and have fixed a number of issues. >

Re: [Wireshark-dev] Various problems with tshark

2015-08-30 Thread Pascal Quantin
Hi Jörg, 2015-08-31 5:34 GMT+02:00 Joerg Mayer : > When using tshark from head I have a bunch of problems right now: > > 1) stderr is getting spammed with > (process:9870): Capture-WARNING **: Dissector stp incomplete in frame > 41915: undecoded byte number 57 (0x0030+9) > You seem to have activ

Re: [Wireshark-dev] Various problems with tshark

2015-08-31 Thread Pascal Quantin
2015-08-31 9:05 GMT+02:00 Alexis La Goutte : > > > On Mon, Aug 31, 2015 at 8:17 AM, Pascal Quantin > wrote: > >> Hi Jörg, >> >> 2015-08-31 5:34 GMT+02:00 Joerg Mayer : >> >>> When using tshark from head I have a bunch of problems right now: >&g

Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-31 Thread Pascal Quantin
Le 31 août 2015 10:09 AM, "Anders Broman" a écrit : > > > > > > From: wireshark-dev-boun...@wireshark.org [mailto: wireshark-dev-boun...@wireshark.org] On Behalf Of Alexis La Goutte > Sent: den 31 augusti 2015 09:43 > To: Developer support list for Wireshark > Subject: Re: [Wireshark-dev] MSVC 201

Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-31 Thread Pascal Quantin
2015-08-31 18:10 GMT+02:00 Bill Meier : > On 8/31/2015 4:24 AM, Pascal Quantin wrote: > >> > May be directly move to GeoIP 2 ? >> > https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10658 >> > >> > >> > >> > I think the code is

Re: [Wireshark-dev] MSVC 2015 (VC14) notes/issue

2015-08-31 Thread Pascal Quantin
2015-08-31 10:24 GMT+02:00 Pascal Quantin : > > Le 31 août 2015 10:09 AM, "Anders Broman" a > écrit : > > > > > > > > > > > > From: wireshark-dev-boun...@wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] On Behalf Of A

Re: [Wireshark-dev] Various problems with tshark

2015-08-31 Thread Pascal Quantin
2015-08-31 21:07 GMT+02:00 Joerg Mayer : > Hello Pascal, > > thanks for the quick response - solved my immediate problem ;-) > > On Mon, Aug 31, 2015 at 08:17:44AM +0200, Pascal Quantin wrote: > > 2015-08-31 5:34 GMT+02:00 Joerg Mayer : > > > > > When usin

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-09-01 Thread Pascal Quantin
alled - loopback interface is still working after a suspend / resume Thanks for your work and congratulation for your GSoC. I guess (hope?) it was considered as being successful :) Pascal. > > > Cheers, > Yang > > > On Fri, Aug 28, 2015 at 4:17 AM, Pascal Quantin &g

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-09-01 Thread Pascal Quantin
2015-09-01 17:23 GMT+02:00 Pascal Quantin : > > > 2015-09-01 3:19 GMT+02:00 Yang Luo : > >> Hi Pascal, >> >> Thanks for this bug. This bug is because loopback flag in Npcap driver >> isn't set when the driver is paused and restarted (occurs when syste

Re: [Wireshark-dev] Npcap 0.04 call for test

2015-09-02 Thread Pascal Quantin
2015-09-02 8:38 GMT+02:00 Yang Luo : > Hi Pascal, > > On Wed, Sep 2, 2015 at 1:57 AM, Pascal Quantin > wrote: > >> >> >> 2015-09-01 17:23 GMT+02:00 Pascal Quantin : >> >>> >>> >>> 2015-09-01 3:19 GMT+02:00 Yang Luo : >>>

Re: [Wireshark-dev] tvb_captured_length or tvb_reported_length?

2015-09-02 Thread Pascal Quantin
Hi Robert, 2015-09-02 19:33 GMT+02:00 Robert Cragie : > > I am trying to understand the changes to the previous use of tvb_length(). > There are now two functions (and their associates): > > * tvb_captured_length() > * tvb_reported_length() > > As far as I can tell, tvb_captured_length() is the d

Re: [Wireshark-dev] tvb_captured_length or tvb_reported_length?

2015-09-02 Thread Pascal Quantin
2015-09-02 19:37 GMT+02:00 Evan Huus : > Many systems support packet capture such that only the first n bytes > of each captured packet is saved, as this is far more efficient and > frequently enough if you're only interested in the headers. When that > occurs, "captured" is the number of bytes ac

Re: [Wireshark-dev] code.wireshark.org down?

2015-09-03 Thread Pascal Quantin
2015-09-03 13:04 GMT+02:00 Robert Cragie : > I can't access https://code.wireshark.org/review - is it down? > Hi Robert, I also get a 502 proxy error. We'll need to wait for Gerald's maintenance I guess. Pascal. ___ Sent vi

Re: [Wireshark-dev] IAX2 and LTE captures

2015-09-03 Thread Pascal Quantin
2015-09-03 19:14 GMT+02:00 Gerald Combs : > Is there a trick to getting the LTE dialogs to show any data? (The trick > with the IAX2 dialog was to remove a no-longer-valid check...) > LTE dialogs require to have LTE MAC/RLC packets captured. Martin, do you have any catapult capture you could priv

Re: [Wireshark-dev] code.wireshark.org down?

2015-09-03 Thread Pascal Quantin
rk ! [remote rejected] HEAD -> refs/for/master (no new changes) error: failed to push some refs to 'ssh:// pas...@code.wireshark.org:29418/wireshark' Thanks, Pascal. > On 9/3/15 4:15 AM, Pascal Quantin wrote: > > > > 2015-09-03 13:04 GMT+02:00 Robert Cragie > <m

Re: [Wireshark-dev] code.wireshark.org down?

2015-09-03 Thread Pascal Quantin
2015-09-03 19:46 GMT+02:00 Pascal Quantin : > > > 2015-09-03 18:00 GMT+02:00 Gerald Combs : > >> I ended up "fixing" the issue by rebooting the server. Still trying to >> track down the initial cause. >> > > Is it fully up and running? When trying to

Re: [Wireshark-dev] Improve the loopback wiki page

2015-09-04 Thread Pascal Quantin
Hi Yang, 2015-09-01 4:09 GMT+02:00 Yang Luo : > Hi Pascal, > > On Fri, Aug 28, 2015 at 2:54 AM, Pascal Quantin > wrote: > >> >> Le 25 août 2015 3:41 PM, "Yang Luo" a écrit : >> > >> > Hi list, >> > >> > I noticed t

Re: [Wireshark-dev] Optommp Dissector into Stable

2015-09-09 Thread Pascal Quantin
2015-09-09 17:14 GMT+02:00 John Miner : > Will you reconsider getting the optommp dissector into stable? > > Hi John, no it will no be considered as a stable branch only gets bug fixes and no enhancements, as explained in our release policy: https://wiki.wireshark.org/Development/ReleasePolicy Un

Re: [Wireshark-dev] Petri-Dish circumvention breaks daily-build

2015-09-09 Thread Pascal Quantin
Le 10 sept. 2015 8:00 AM, "Roland Knall" a écrit : > > Hi > > In our company we have our own Wireshark tools and plugins, which use the main wireshark repository. To ensure that those do not break (and if they break we can fix them in due time), we synchronize with the Wireshark repo every night a

Re: [Wireshark-dev] Petri-Dish circumvention breaks daily-build

2015-09-09 Thread Pascal Quantin
re). Pascal. > > regards, > Roland > > On Thu, Sep 10, 2015 at 8:30 AM, Pascal Quantin wrote: >> >> >> Le 10 sept. 2015 8:00 AM, "Roland Knall" a écrit : >> > >> > Hi >> > >> > In our company we have our own Wireshar

Re: [Wireshark-dev] Remove duplication for resolved addresses

2015-09-10 Thread Pascal Quantin
Hi, 2015-09-10 13:50 GMT+02:00 João Valverde : > Hi list, > > I proposed a change[1] to remove the duplication for resolved addresses > (not necessarily using that code) in the UI: > > Src: 192.0.2.1, Dst: 192.0.2.2 > > Instead of: > > Src: 192.0.2.1 (192.0.2.1), Dst: 192.0.2.2 (192.0.2.2) >

Re: [Wireshark-dev] Remove duplication for resolved addresses

2015-09-10 Thread Pascal Quantin
2015-09-10 22:31 GMT+02:00 Guy Harris : > > On Sep 10, 2015, at 1:05 PM, Pascal Quantin > wrote: > > > Just a random thought (as I'm far from being a script expert). In case > only one of the 2 IP address is resolved, would it be harder to parse? > > Src: 192.

Re: [Wireshark-dev] Wireshark "Decode As"

2015-09-15 Thread Pascal Quantin
Hi João, Le 15 sept. 2015 4:41 PM, "João Valverde" a écrit : > > Hi, > > I'm trying to understand and troubleshoot some "Decode As" issues. To give an example consider the packet: > > IPv6 | IPv6 | UDP > > Wouldn't the second IPv6 layer overwrite the Decode As protocol number for the first layer,

Re: [Wireshark-dev] Wireshark "Decode As"

2015-09-15 Thread Pascal Quantin
2015-09-15 21:15 GMT+02:00 João Valverde : > > > On 09/15/2015 07:38 PM, Pascal Quantin wrote: > >> Hi João, >> >> Le 15 sept. 2015 4:41 PM, "João Valverde" >> > <mailto:joao.valve...@tecnico.ulisboa.pt>> a écrit : >> > >>

Re: [Wireshark-dev] Wireshark "Decode As"

2015-09-15 Thread Pascal Quantin
2015-09-15 22:39 GMT+02:00 João Valverde : > > > On 09/15/2015 09:05 PM, Pascal Quantin wrote: > >> >> >> 2015-09-15 21:15 GMT+02:00 João Valverde >> > <mailto:joao.valve...@tecnico.ulisboa.pt>>: >> >> >> >> On 09/15/2015

Re: [Wireshark-dev] Wireshark "Decode As"

2015-09-15 Thread Pascal Quantin
2015-09-15 23:20 GMT+02:00 João Valverde : > > > > On 09/15/2015 09:43 PM, Pascal Quantin wrote: >> >> >> >> 2015-09-15 22:39 GMT+02:00 João Valverde >> > <mailto:joao.valve...@tecnico.ulisboa.pt>>: >> >> >> >> On 0

Re: [Wireshark-dev] Wireshark "Decode As"

2015-09-16 Thread Pascal Quantin
2015-09-16 0:55 GMT+02:00 Pascal Quantin : > > 2015-09-15 23:20 GMT+02:00 João Valverde >: > > > > > > > > On 09/15/2015 09:43 PM, Pascal Quantin wrote: > >> > >> > >> > >> 2015-09-15 22:39 GMT+02:00 João Valverde > >>

Re: [Wireshark-dev] The journey of a thousand miles...

2015-09-21 Thread Pascal Quantin
Hi Michael, 2015-09-21 4:48 GMT+02:00 : > ... begins with a single step - Lao Tzu > > > The thousand mile journey has been completed as all proto_tree_add_text > calls within the Wireshark source have been converted to a "better" API. > Because they have been converted, I think proto_tree_add_tex

Re: [Wireshark-dev] Coredump with wireshark TCP dissector

2015-09-29 Thread Pascal Quantin
Le 29 sept. 2015 4:13 PM, "Garrett Kajmowicz" a écrit : > > I'm running Ubuntu. I used Wireshark (package: 1.12.1+g01b65bf-4+deb8u2build0.15.04.1) to capture an NFS packet trace, attempting to understand some latency issues with some applications. Packet trace came out to about 35 MiB. > > Attempt

Re: [Wireshark-dev] Windows driver signing certificate purchase decision for WinPcap and Npcap

2015-10-01 Thread Pascal Quantin
Hi all, in my company we just received the following email from Symantec indicating that the EV signing will soon be mandatory: "On October 27, 2015, all new Kernel and User Mode driver submissions will need to be made via the Windows Hardware Developer Center Dashboard portal and signed by an Ex

Re: [Wireshark-dev] Improving the SSL keys dialog, how to handle migrations?

2015-10-03 Thread Pascal Quantin
Hi Peter, Some general comments in-line. I'm not a user of SSL/DTLS dissectors so I do not have any real suggestion for your proposals. Le 3 oct. 2015 6:53 PM, "Peter Wu" a écrit : > > Hi, > > So far SSL/DTLS private RSA key files were entered in an UAT dialog > (ssl_keys) using address, port, p

Re: [Wireshark-dev] Index of multiple protocol frames in one packet?

2015-10-05 Thread Pascal Quantin
2015-10-06 8:07 GMT+02:00 Petr Gotthard : > Hello, > > Is there a way to distinguish multiple frames of the same protocol in one > TCP/IP packet? I have several small AMQP frames which all fit into a single > IP frame, so they share a single packet_info structure.When I call > p_add_proto_data() f

Re: [Wireshark-dev] [Wireshark-commits] master a37ac98: SCTP: fix dissection of DATA chunks

2015-10-07 Thread Pascal Quantin
ireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a37ac98c5eb5c44794ca36418f93e7ed1c3e0af5 > > Submitter: Pascal Quantin (pascal.quan...@gmail.com) > > Changed: branch: master > > Repository: wireshark > > > > Commits: > > > > a37ac98 by Pascal Quantin (pascal.quan...

Re: [Wireshark-dev] Index of multiple protocol frames in one packet?

2015-10-12 Thread Pascal Quantin
2015-10-12 17:35 GMT+02:00 Jeff Morriss : > On 10/06/15 02:17, Pascal Quantin wrote: > >> >> >> 2015-10-06 8:07 GMT+02:00 Petr Gotthard > <mailto:petr.gotth...@centrum.cz>>: >> >> Hello, >> >> Is there a way to distinguish mult

Re: [Wireshark-dev] QT SDK for Win 10 x64

2015-10-18 Thread Pascal Quantin
2015-10-17 17:29 GMT+02:00 Mohammed Al-Moayed : > Hi All, > > I tried to download the QT sdk as mentioned in the Dev guide but I didn't > find a free one. could you please help me with the download link. And what > could be the solution if there is no version for win 10 x64? > Hi Mohammed, you c

Re: [Wireshark-dev] Extcap

2015-10-19 Thread Pascal Quantin
Le 19 oct. 2015 2:30 PM, "Dario Lombardo" a écrit : > > I'm playing with extcap, but I can't make it fully work. > I can run androiddump, and I can list the interfaces. > > # ./run/extcap/androiddump --extcap-interfaces > interface {display=Android Logcat Main}{value=android-logcat-main-XX

Re: [Wireshark-dev] Wonder should recognize VxLAN packet with UDP destination port number 4789 but not source port.

2015-10-22 Thread Pascal Quantin
Hi Michael, 2015-10-21 8:13 GMT+02:00 Michael : > Hi everyone, > > > > I just want to know if I misunderstood RFC 7348 ( > https://tools.ietf.org/html/rfc7348 ). > > According to section 5 – VXLAN Frame Format, it seems just UDP.Dst-Port > must/should be 4789. > > > > But I have checked the code:

Re: [Wireshark-dev] Usb dissectors, usb.protocol is always 0x000000

2015-10-23 Thread Pascal Quantin
2015-10-23 16:50 GMT+02:00 [AvataR] : > Hi list. > > I wrote trivial dissector (in lua, if it's matters) for MTP protocol > for own use. Now I have a problem - how to apply it just for these > packets. > > I reviewed sources and found out, that there is usb.protocol > dissection table. I even foun

Re: [Wireshark-dev] Usb dissectors, usb.protocol is always 0x000000

2015-10-23 Thread Pascal Quantin
2015-10-23 17:30 GMT+02:00 [AvataR] : > > > > Hi, > > > > ensure to capture the USB enumeration. This is required to fill those > > fields. > > > > Best regards, > > Pascal. > > > > To be really sure, I start capture before plugging device to hub. > There are enumeration, and descriptors are prope

Re: [Wireshark-dev] Usb dissectors, usb.protocol is always 0x000000

2015-10-24 Thread Pascal Quantin
2015-10-23 21:01 GMT+02:00 Oleksii Shevchuk : > Pascal Quantin writes: > > I tried wireshark in Debian Jessie (1.12) and on gentoo (1.12.8). > > Screenshot is here - https://alxchk.me/scr.png > Dump is here - https://alxchk.me/dump.pcapng.gz Hi Oleksii, Thanks for the captur

Re: [Wireshark-dev] GTP session plugin

2015-11-02 Thread Pascal Quantin
2015-11-02 16:20 GMT+01:00 POZUELO Gloria (BCS/PSD) : > Hello! > > I would like to ask you about a problem that I encountered while working > in this development. I need to get the IP dst from the packet information > and convert it to string (char *), but by inspecting the type _address I > can s

Re: [Wireshark-dev] GTP session plugin

2015-11-02 Thread Pascal Quantin
. See doc/README.wmem for more information. BR, Pascal. > > *From:* wireshark-dev-boun...@wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] *On Behalf Of *Pascal Quantin > *Sent:* Monday 2 November 2015 16:29 > *To:* Developer support list for Wireshark > *Subject:* Re:

Re: [Wireshark-dev] GTP sequence number equal to zero problem

2015-11-03 Thread Pascal Quantin
2015-11-03 16:13 GMT+01:00 POZUELO Gloria (BCS/PSD) : > Hi all, > > > > I’m developing an extension for the GTPv1 dissector and while I was > debugging I’ve encountered something that it seems to me a bit confusing. > In the dissect_gtp_common function from the packet-gtp.c source, there is a > se

Re: [Wireshark-dev] GTP session plugin

2015-11-11 Thread Pascal Quantin
wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] *On Behalf Of *Pascal Quantin > *Sent:* Monday 2 November 2015 17:11 > > *To:* Developer support list for Wireshark > *Subject:* Re: [Wireshark-dev] GTP session plugin > > > > > > > > 2015-11-02

Re: [Wireshark-dev] When is the preference variable updated?

2015-11-12 Thread Pascal Quantin
2015-11-12 15:07 GMT+01:00 Paul Offord : > Hi, > > > > Frankly I feel a bit stupid asking this but I've been trying to figure it > out for about 6 hours and I think I need help. I have a dissector which I > register like this: > > > > static int tmsvc_port = 0; > > > > void > > proto_register_tms

Re: [Wireshark-dev] When is the preference variable updated?

2015-11-12 Thread Pascal Quantin
solution should be the same as mine (or maybe I was not clear): proto_reg_handoff_tmsvc should be given as parameter to perfs_register_protocol and you will see that this function starts being called several times (so you should probably ensure that your code is called only once). > > >

Re: [Wireshark-dev] What is the reason that the 64-bit version of Wireshark is not compiled with Kerberos?

2015-11-17 Thread Pascal Quantin
2015-11-17 21:37 GMT+01:00 Richard Sharpe : > Hi folks, > > On 1.12.8 8 it says without Kerberos. > > Do I need to also install the 32-bit version of Wireshark or is there > a way to fix the build for the 64-bit version so it also builds with > Kerberos? > Hi Richard, Kerberos support was added

Re: [Wireshark-dev] Review of Gerrit patch for RTPS

2015-11-18 Thread Pascal Quantin
Hi Juan, 2015-11-18 17:36 GMT+01:00 Juan Jose Martin Carrascosa : > Hi everyone, > > It has been almost two weeks and I am surprised I still didn't have a > review here. I am surprised because I always get reviews very early! (in > the first 24h, which is awesome). > > https://code.wireshark.org/

Re: [Wireshark-dev] Review of Gerrit patch for RTPS

2015-11-18 Thread Pascal Quantin
:) > > Thanks, > Juanjo Martin > > > On Wednesday, November 18, 2015, Pascal Quantin > wrote: > >> Hi Juan, >> >> 2015-11-18 17:36 GMT+01:00 Juan Jose Martin Carrascosa : >> >>> Hi everyone, >>> >>> It has been almost tw

Re: [Wireshark-dev] Review of Gerrit patch for RTPS

2015-11-19 Thread Pascal Quantin
d that you were busy. Thanks for the answer. >>> >>> Is there anything I can help with? I may be able to spend some hours >>> this weekend. >>> >>> Thanks, >>> Juanjo Martin >>> >>> On Wednesday, November 18, 2015, Pascal Quantin

Re: [Wireshark-dev] Capture PPP on Windows Vista

2015-11-23 Thread Pascal Quantin
2015-11-23 19:47 GMT+01:00 Alexis La Goutte : > Hi Michal, > > Do you have try npcap or Win10pcap ? because it is NDIS 6.0 ready (and > winpcap is only NDIS 5 for the moment...) > I do not think any of them support PPP neither (I cannot find any reference to ndiswanbh in Npcap source code). Let's

Re: [Wireshark-dev] NSIS packaging not working

2015-11-27 Thread Pascal Quantin
2015-11-27 8:11 GMT+01:00 POZUELO Gloria (BCS/PSD) : > Hello everyone, > > I'd like to ask you about wireshark packaging. I'm trying to build a x64 > version and when I execute these commands: > > > msbuild /m /p:Configuration=RelWithDebInfo nsis_package_prep.vcxproj > > > msbuild /m /p:Configura

Re: [Wireshark-dev] NSIS packaging not working

2015-11-27 Thread Pascal Quantin
> File /r "F:\Development\run\Debug\platforms" > File /r "F:\Development\run\Debug\playlistformats" > File /r "F:\Development\run\Debug\printsupport" > > And I don’t see any error when executing the nsis_package_prep project. > The result is 17 succeed

Re: [Wireshark-dev] create_dissector_handle - what's occuring?

2015-11-29 Thread Pascal Quantin
2015-11-29 21:14 GMT+01:00 Paul Offord : > I was a relatively happy camper until about 30 mins ago when I did a git > pull to refresh my build environment. Now IntelliSense is telling me that > create_dissector_handle is an unfound identifier. > > > > I notice that new_create_dissector_handle has

[Wireshark-dev] Moving codecs to libwireshark or libwsutil?

2015-11-30 Thread Pascal Quantin
Hi all, I tried to create a codecs plugin for Windows, but the plugin registration fails. As reported previously on this list ( https://www.wireshark.org/lists/wireshark-dev/201409/msg00043.html), this because the plugin itself ends with its own copy of register_codec function instead of using on

Re: [Wireshark-dev] Moving codecs to libwireshark or libwsutil?

2015-11-30 Thread Pascal Quantin
2015-11-30 15:40 GMT+01:00 Pascal Quantin : > Hi all, > > I tried to create a codecs plugin for Windows, but the plugin registration > fails. > > As reported previously on this list ( > https://www.wireshark.org/lists/wireshark-dev/201409/msg00043.html), this > because the

Re: [Wireshark-dev] Moving codecs to libwireshark or libwsutil?

2015-11-30 Thread Pascal Quantin
Le 30 nov. 2015 8:01 PM, "Guy Harris" a écrit : > > > On Nov 30, 2015, at 6:40 AM, Pascal Quantin wrote: > > > Should we move codecs functions to one of the existing libraries? Or add it to its own? > > They already *are* in their own library, but it's

Re: [Wireshark-dev] Wireshark Performance

2015-12-02 Thread Pascal Quantin
2015-12-02 16:12 GMT+01:00 POZUELO Gloria (BCS/PSD) : > Where can I find that option? > On Windows, Ctrl + Shift + E, or in the menu Analyze -> Enabled protocols. Unselect stun_udp. > > > *From:* wireshark-dev-boun...@wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] *On Behalf Of *A

Re: [Wireshark-dev] Wireshark Performance

2015-12-02 Thread Pascal Quantin
Pascal. > > *From:* wireshark-dev-boun...@wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] *On Behalf Of *Pascal Quantin > *Sent:* den 2 december 2015 16:26 > > *To:* Developer support list for Wireshark > *Subject:* Re: [Wireshark-dev] Wireshark Performance > >

Re: [Wireshark-dev] Moving codecs to libwireshark or libwsutil?

2015-12-02 Thread Pascal Quantin
2015-11-30 20:15 GMT+01:00 Guy Harris : > > On Nov 30, 2015, at 11:07 AM, Pascal Quantin > wrote: > > > > Yes I should have been clearer in my initial description. > > My suggestion with an extra parameter giving the hash table address is > also working fine, so

Re: [Wireshark-dev] Question regarding LTE RRC dissectors

2015-12-02 Thread Pascal Quantin
2015-12-02 23:36 GMT+01:00 Jagadeesan, Viswanathan < vjaga...@qti.qualcomm.com>: > > > > > *From:* Jagadeesan, Viswanathan > *Sent:* Wednesday, December 02, 2015 5:35 PM > *To:* 'pascal.quan...@gmail.com' > *Subject:* Question regarding LTE RRC dissectors > > > > Hi > > > > followup quest

Re: [Wireshark-dev] Question regarding LTE RRC dissectors

2015-12-02 Thread Pascal Quantin
dentifying the LTE RRC channel and the message payload, then calling the right dissector. All are registered by name (as seen in packet-lte-rrc.c) and can be called from a plugin. You should not try to duplicate LTE RRC code. > > > > Any suggestions. > > > > Thanks,Viswa >

Re: [Wireshark-dev] Dissector code feedback request (Cassandra CQL)

2015-12-08 Thread Pascal Quantin
2015-12-08 22:46 GMT+01:00 Aaron Ten Clay : > On 03 Dec 2015, you wrote: > > > On Thu, Dec 3, 2015 at 9:27 AM, wrote: > > > > > Hello everyone, > > > > > > I've started cobbling together a dissector plugin for the CQL binary > > > protocol used by Apache Cassandra. I'm brand new to Wireshark > de

Re: [Wireshark-dev] Replacing GHashTable with wmem_map_t

2015-12-09 Thread Pascal Quantin
Hi Gloria Hello, I’d like to ask you about the new API. I’m replacing the GHashTable type with wmem_map_t and I don’t know how can iterate through the wmem_map, as we can do it with GHashTable by using g_hash_table_iter methods. Thank you in advance, Regards.

Re: [Wireshark-dev] Replacing GHashTable with wmem_map_t

2015-12-09 Thread Pascal Quantin
ase do not forget to clean memory if required). Or maybe this is a sign you should use a tree instead of a hash map. Pascal. > > *From:* wireshark-dev-boun...@wireshark.org [mailto: > wireshark-dev-boun...@wireshark.org] *On Behalf Of *Pascal Quantin > *Sent:* Wednesday 9 December 201

Re: [Wireshark-dev] Doc: Broken internal Link

2015-12-10 Thread Pascal Quantin
Hi Thomas 2015-12-09 17:21 GMT+01:00 Thomas Güttler : > Hi, > > there is an broken internal link/reference: > > > https://www.wireshark.org/docs/wsug_html_chunked/ChWorkBuildDisplayFilterSection.html > > in "Tip": at > wireshark-wiki-display-filter:[wireshark-wiki-display-filter:[]] > Thanks for

Re: [Wireshark-dev] Chained CAN dissecector: Can not get reference for CAN dissector

2015-12-15 Thread Pascal Quantin
2015-12-15 11:37 GMT+01:00 Sebastian Schildt : > > Hello Wiresharkers, > > I have a problem (obviously :) ) . I want to create a CAN dissector (in > Lua). What I already achieved is creating a Can subdissector: So my > dissector gets called for CAN payload. However, I need access to the CAN > ide

Re: [Wireshark-dev] Call XML and JSON dissectors with new HTTP Content-Type

2015-12-17 Thread Pascal Quantin
Hi Juan, 2015-12-17 13:40 GMT+01:00 Juan Jose Martin Carrascosa : > Hi all, > > Web Integration Service (http://www.omg.org/spec/DDS-WEB/1.0/Beta2/) is a > new service that sends/receives DDS traffic (RTPS) over HTTP. The > serialization is not directly RTPS but a conversion handled internally, >

Re: [Wireshark-dev] build with vs2015

2015-12-31 Thread Pascal Quantin
Le 31 déc. 2015 6:03 PM, "Alan Partis" a écrit : > > What about even building on Windows 10? I see that Qt 5.5 has a Windows > Runtime for 8.1, but I don't see the same thing for Windows 10. Qt 5.5 (and earlier versions as the official Wireshark binary is built with Qt 5.3.2) run without any iss

Re: [Wireshark-dev] Current C-Standard used in wireshark

2016-01-02 Thread Pascal Quantin
Le 2 janv. 2016 12:04 PM, "Thomas Wiens" a écrit : > > Hi, > > I just updated my local wireshark sources and wanted to build wireshark > with Win32 / VC10.0, when compiling failed at extcap/randpktdump.c, line > 297, due to variable declaration inside code which is not C89 compliant. > > The READM

Re: [Wireshark-dev] rrc-lte over udp

2016-01-02 Thread Pascal Quantin
Le 2 janv. 2016 9:22 PM, "Karunkaran Kumar" a écrit : > > Hi all, > > I recently learned about the LTE support on wireshark -- mac-lte, rlc-lte, pdcp-lte and rrc-lte. > The heuristic dissection (i.e., using UDP framing) of the lower layers (i.e., mac,rlc,pdcp) fits my needs exactly. > However, the

Re: [Wireshark-dev] rrc-lte over udp

2016-01-03 Thread Pascal Quantin
} Where 0x000C corresponds to EXP_PDU_TAG_PROTO_NAME option, 0x0014 to the option length, then the dissector name "lte_rrc.bcch_dl_sch", followed by a padding (as the option must be a multiple of words), then the EXP_PDU_TAG_END_OF_OPT option (0x0000) and a null length for this option (0x0

Re: [Wireshark-dev] pinfo->fd->flags.visited for wireshark c dissector

2016-01-06 Thread Pascal Quantin
2016-01-06 8:30 GMT+01:00 Ran Bao : > Hi > > I am currently implementing a dissector plugin for a DMR conventional and > trunked protocols. Three layers of protocols were involved. Messages was > send to a specific UDP port on server. > > > > UDP port -> Company specified protocol -> DMR Layer 2 P

Re: [Wireshark-dev] Plugin Version

2016-01-18 Thread Pascal Quantin
Hi Paul, 2016-01-18 14:37 GMT+01:00 Paul Offord : > Hi, > > > > I’m having problems setting the Version information for a plugin I have > developed. I’ve changed the version information in moduleinfo.nmake: > > > > # The version > > MODULE_VERSION_MAJOR=0 > > MODULE_VERSION_MINOR=99 > > MODULE_V

Re: [Wireshark-dev] Automated Builds

2016-01-18 Thread Pascal Quantin
Hi David, 2016-01-18 22:36 GMT+01:00 David Morsberger : > Is there an issue with the automated build server. I see the last win64 > build was on 15-Jan at 09:03. > > I am hoping to test a win64 version tonight with at least merge set > 7002a9cb3f23f2af2c95352d01eb557753d299c5 > According to http

Re: [Wireshark-dev] building errors for wireshark

2016-02-01 Thread Pascal Quantin
Hi Tengfei, 2016-02-01 16:30 GMT+01:00 Tengfei Chang : > Dear all, > > Recently I am trying to build my own wireshark. I followed with the > tutorial here: > https://www.wireshark.org/docs/wsdg_html_chunked/ChSetupWin32.html > > Everything works fine before I build it, where I got tons of errors.

Re: [Wireshark-dev] Wireshark fails to start with wpcap.dll built by Visual Studio 2010

2016-02-03 Thread Pascal Quantin
2016-02-03 16:16 GMT+01:00 Yang Luo : > Hi list, > > After several months, I retried updating wpcap project from VS 2005 to VS > 2010) and encountered the same issue, under Wireshark 2.0.1 x64, Win10 x64. > > The Wireshark UI said "Child dumpcap process died: Access violation". I > don't know what

Re: [Wireshark-dev] Compiling Wireshark with gcc-6: Lots of new warnings

2016-02-10 Thread Pascal Quantin
Hi Alexis, 2016-02-10 13:00 GMT+01:00 Alexis La Goutte : > Hi, i have now a build machine with gcc6 and try.. > There is always some warning, i have push a first serie of patch > https://code.wireshark.org/review/#/q/topic:gcc6 > > For dissectors, the last one is : > ../../asn1/q932/packet-q932-e

Re: [Wireshark-dev] pre-commit ImportError

2016-02-16 Thread Pascal Quantin
Hi Gloria, 2016-02-17 8:48 GMT+01:00 POZUELO Gloria (BCS/PSD) : > Hello, > > > > I’d like to ask you about a problem with the pre-commit hook. It turns out > that when I try to commit my changes it shows me a message that says: > “ImportError: No module named site”, but when I delete the pre-com

Re: [Wireshark-dev] Bit for starting / stopping / new Capture

2016-02-17 Thread Pascal Quantin
Hi Tobias, 2016-02-17 16:16 GMT+01:00 FIXED-TERM Scholz Tobias (DC-IA/EAI) < fixed-term.tobias.sch...@boschrexroth.de>: > Hey, > > I made some recherché, but couldn’t find any information to this topic. Is > there a possibility to know (special bit for example), whether the user > stopped, starte

  1   2   3   4   5   6   7   8   9   >