Ask Your Question

Guy Harris's profile - activity

2021-10-18 22:41:08 +0000 commented question Second bit set to false

Or do you mean "the second bit in the raw packet data"?

2021-10-18 19:20:51 +0000 commented question Updating Wireshark without removing pcap library

On what operating system are you doing this?

2021-10-15 20:18:43 +0000 commented answer zipcode of network

And here's a latitude & longitude to ZIP code lookup service. It says "1 Credit per Lookup", so you may get a limit

2021-10-15 07:18:38 +0000 edited question Wireshark shows only the length column in a Wi-Fi capture

Wireshark only capture length. I am using last version of kali 2021.3 kali-rolling. Today I pass through 4.9 version o

2021-10-15 07:17:44 +0000 commented question Wireshark shows only the length column in a Wi-Fi capture

What does it display if you open up the "Frame 1" entry in the packet details pane? (For some reason, image links don't

2021-10-14 23:14:26 +0000 answered a question Please fix in-app upgrade

This site is for asking questions about using Wireshark. Bugs and requests for improvement should be posted as issues o

2021-10-14 23:14:26 +0000 received badge  Rapid Responder (source)
2021-10-14 23:11:20 +0000 commented answer Capture filter help needed

And more should be added to that code to support string and byte-sequence comparisons at a particular offset and to supp

2021-10-14 23:09:27 +0000 commented answer Capture filter help needed

I don't think it's a particularly large leap to go from a capture filter syntax to BPF instructions, $ wc -l gencod

2021-10-14 23:06:45 +0000 received badge  Rapid Responder (source)
2021-10-14 23:06:45 +0000 answered a question zipcode of network

is it possible to determine the zip code in which a network is operating from the network traffic using wireshark N

2021-10-14 22:26:13 +0000 commented answer Can Mergecap merge captures in a different directory than where it is located?

Add the folder that Wireshark folder, e.g. "c:\Program Files\Wireshark\", closed all the windows and then restart. Me

2021-10-13 18:10:55 +0000 edited question Windows 11 install fails

Windows 11 Support When installing on a Windows 11 VM i get the error below. Neither mentioned KB is applicable, so it

2021-10-13 18:10:21 +0000 edited question Windows 11 install fails

Windows 11 Support When installing on a Windows 11 VM i get the error below. Neither mentioned KB is applicable, so it

2021-10-12 21:11:03 +0000 commented question can not see SIP protocol in my wireshark

There is not enough information available to determine what the issue is. There could be many causes (traffic is on a "

2021-10-01 02:11:21 +0000 edited question Marlformed Resultdata 16 INAP trace

Marlformed Resultdata 16 INAP trace Hello , Someone has faced this issue trying to decoded INAP traces? I can decode

2021-10-01 02:10:53 +0000 commented question Error Vector Length

What protocol is this?

2021-09-27 00:36:54 +0000 commented question How do I capture more features

So by "features" do you mean "the items that show up in the part of this display that has stuff such as Questions: 1"?

2021-09-27 00:36:24 +0000 commented question How do I capture more features

So by "features" do you mean "the items that show up in the part of this display that has stuff such as Questions: 1"?

2021-09-22 08:17:51 +0000 received badge  Rapid Responder (source)
2021-09-22 08:17:51 +0000 answered a question How do I let the user specify for which UDP ports a dissector should be used?

I created a dissector under the assumption that a given dissector is applied to every packet picked up by Wireshark.

2021-09-22 08:11:12 +0000 edited question How do I let the user specify for which UDP ports a dissector should be used?

is a given dissector applied to every packet? I created a dissector under the assumption that a given dissector is appli

2021-09-16 08:03:07 +0000 received badge  Rapid Responder (source)
2021-09-16 08:03:07 +0000 answered a question Dissector doesn't see retransmission packets

This has nothing to do with Lua; it has to do with the way the TCP dissector handles retransmissions. If it's a retrans

2021-09-16 08:00:57 +0000 edited question Dissector doesn't see retransmission packets

LUA and retransmission packets Hello, my dissector is registered to decode a bunch of ports: tcp_table = DissectorTabl

2021-09-15 02:45:32 +0000 received badge  Rapid Responder (source)
2021-09-15 02:45:32 +0000 answered a question Wireshark not displaying packets on my LAN for iPhone

If you're capturing in monitor mode, then, if you're on a "protected" network (with WEP or WPA encryption), the packets

2021-09-13 05:46:50 +0000 commented question Can the time column represent the transmission time?

Transmission time is defined as: the total time the frame takes to transmit data By that do you mean the difference

2021-09-12 02:00:01 +0000 commented question Capture filter not capturing anything

Ok I have figured out that this problem only occurs if I have the network tap positioned between the wall and the rou

2021-09-11 21:29:20 +0000 commented question Capture filter not capturing anything

Even if I do a capture filter of 'ip' it doesn't capture anything. What if you have no capture filter?

2021-09-11 09:52:23 +0000 commented question Capture filter not capturing anything

When I run a capture using 'host xxx.xxx.xxx.xxx' as a capture filter it does not capture anything even though I know

2021-09-10 07:33:56 +0000 received badge  Rapid Responder (source)
2021-09-10 07:33:56 +0000 answered a question What is the difference between packet Inter arrival time and time delta from previous captured frame.

On my packet capture on Wireshark I have a column called "time delta from previous captured frame" as well as "time d

2021-09-08 07:07:11 +0000 edited question Wireshark reassembly stops working after "TCP previous segment not captured"

Wireshark reassembly stops working after "TCP previous segment not captured"" I'm analiayze the rtp's packet over TCP by

2021-09-08 07:06:52 +0000 edited question Wireshark reassembly stops working after "TCP previous segment not captured"

LUA Dissector is not run on retransmitted TCP segments I'm analiayze the rtp's packet over TCP by wireshark's dissector.

2021-09-08 07:06:05 +0000 received badge  Rapid Responder (source)
2021-09-08 07:06:05 +0000 answered a question Wireshark reassembly stops working after "TCP previous segment not captured"

The problem has nothing to do with Lua. It has to do with the capture not having all the packets in the TCP flow from 3

2021-09-03 20:51:12 +0000 answered a question Dissector: register a name for a ethertype

You'd have to modify the etype_vals[] table in epan/dissectors/packet-ethertype.c and recompile Wireshark; unfortunately

2021-09-03 20:51:12 +0000 received badge  Rapid Responder (source)
2021-09-03 06:29:30 +0000 edited answer Can wireshark be used with usb to ethernet adapters?

If by "USB to Ethernet adapters" you mean "USB Ethernet adapters", i.e. Ethernet adapters that are not built into the ma

2021-09-03 06:28:21 +0000 received badge  Rapid Responder (source)
2021-09-03 06:28:21 +0000 answered a question Can wireshark be used with usb to ethernet adapters?

If by "USB to Ethernet adapters" you mean "a USB Ethernet adapter", i.e. an Ethernet adapter that's not built into the m

2021-09-02 03:19:44 +0000 edited question Why are packets captured on "\Device\NPF_Loopback" shown with a red background?

Red Flag "\Device\NPF_Loopback" Hi, i hope anyone can tell me why wireshark flags the packages on the Screenshot in re

2021-08-30 19:10:43 +0000 edited question CMake problems with building with with Qt 6 on Windows

new build issues I was following the step by step guide (https://www.wireshark.org/docs/wsdg_html_chunked/ChSetupWin32.h

2021-08-29 00:26:23 +0000 answered a question Is it possible to publish the signatures file with each release set instead of only the signature file for the current main release?

Is it possible to publish the signatures file with each release set instead of only the signature file for the curren

2021-08-29 00:26:23 +0000 received badge  Rapid Responder (source)
2021-08-27 01:01:29 +0000 received badge  Rapid Responder (source)
2021-08-27 01:01:29 +0000 answered a question iOS app capture

If you have a Mac running a sufficiently recent version of macOS (I don't know when "remote virtual interfaces" were add

2021-08-19 23:02:46 +0000 received badge  Rapid Responder (source)
2021-08-19 23:02:46 +0000 answered a question interface XHC20 does not exist (still)

You'll have to ask Apple about that - we just report what macOS's code tells us.