Home page logo
/

wireshark logo Wireshark mailing list archives

Re: [WARNING - NOT VIRUS SCANNED] Negative delta with UDP / SIP conversation
From: Guy Harris <guy () alum mit edu>
Date: Thu, 20 Jun 2013 14:32:05 -0700


On Jun 20, 2013, at 2:14 PM, Pascal Quantin <pascal.quantin () gmail com> wrote:

I have nothing more to add to Guy's really good explanation. But if you are using Wireshark 1.10.0, be aware that it 
comes bundled with a small utility (found in the installation folder) allowing you to reorder a capture file 
according to the packets timestamp. Simply do:

Having an option to do that within Wireshark might be useful as well.

(Having a way for libpcap/WinPcap to fix that problem might also be useful; that might requiring delaying the delivery 
of packets to libpcap's callers until you're pretty sure some packet with a time stamp before that packet won't arrive.)

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault