Hi I have this behaviour that does not quite fall in the FAQ Q-11.
With Ethereal or with my software using mode NDIS_PACKET_TYPE_ALL_LOCAL/NDIS_PACKET_TYPE_PROMISCUOUS, some frames sent from my machine are captured by the machine with only 54 Bytes. The frames (e.g. fromEmule) have 60 Bytes: IP_payload(40B) + SA(6B) + DA(6B) + Type(2B) + Padding(6B) . Looks like the padding after the IP layer is lost. It occurs for FIN and ACK TCP packets. It occurs with Winpcap 2.3 and 3.0, with Windows XP, in different machines, all with Ethernet cards. I don't have any PGP or VPN stuff installed installed. Only XP Firewall. Frames captured sent to my machine or sent by others to others (I have a Hub), are OK. Hints ? Thx Pedro Lucas ================================================================== This is the WinPcap users list. It is archived at http://www.mail-archive.com/[EMAIL PROTECTED]/ To unsubscribe use mailto: [EMAIL PROTECTED] ==================================================================
