Wireshark mailing list archives
Dissect packet without Ethernet data
From: Hoang Thang <ngohoangthang () gmail com>
Date: Wed, 30 Mar 2011 18:11:34 +0700
Hi all bros,
I have 2 pcap files, each of them contains one packet only.
1) Layers: *Ethernet II -> IP -> TCP -> HTP*
2) Layers: *IP -> TCP -> HTP*. This pcap file is extract from (1), that
mean "Ethernet II" is deleted with HEX edit.... And changing size field in
pcap header also.
Problem: I want to open the second file with Wireshark.
Please help me how to modify Wireshark code to dissect (2) correctly. How
many step to register IP layer as root layer ?
Thank you very much,
--
Ngo Hoang Thang
--------------------------
MSN : thang () live com
___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
Current thread:
- Dissect packet without Ethernet data Hoang Thang (Mar 30)
- Re: Dissect packet without Ethernet data Jeff Morriss (Mar 30)
- Re: Dissect packet without Ethernet data Guy Harris (Mar 30)
