Hi

I have this behaviour that does not quite fall in the FAQ Q-11.

With Ethereal or with my software using mode
NDIS_PACKET_TYPE_ALL_LOCAL/NDIS_PACKET_TYPE_PROMISCUOUS, some frames sent
from my machine are captured by the machine with only 54 Bytes. The frames
(e.g. fromEmule) have 60 Bytes: IP_payload(40B) + SA(6B) + DA(6B) + Type(2B)
+ Padding(6B) . Looks like the padding after the IP layer is lost.

It occurs for FIN and ACK TCP packets.
It occurs with Winpcap 2.3 and 3.0, with Windows XP, in different machines,
all with Ethernet cards.
I don't have any PGP or VPN stuff installed installed. Only XP Firewall.
Frames captured sent to my machine or sent by others to others (I have a
Hub), are OK.

Hints ?

Thx
Pedro Lucas



==================================================================
 This is the WinPcap users list. It is archived at
 http://www.mail-archive.com/[EMAIL PROTECTED]/

 To unsubscribe use 
 mailto: [EMAIL PROTECTED]
==================================================================

Reply via email to