Ask Your Question

Guy Harris's profile - activity

2019-04-22 21:47:41 +0000 edited question broken socket while using androiddump

broken socket while using androiddump Error: Error by extcap pipe: (androiddump.exe:3692): GLib-CRITICAL **: g_ascii_s

2019-04-22 21:47:15 +0000 commented question broken socket while using androiddump

i still have the broken pipe problem while using androiddump Error by extcap pipe: ** (androiddump.exe:3412): WARNIN

2019-04-22 17:57:21 +0000 received badge  Rapid Responder (source)
2019-04-22 17:57:21 +0000 answered a question What are possible reasons the source and destination showing as N/A in this PPP traffic?

"PPP" stands for "Point-to-Point Protocol", as in "one and only one host, on one end of the link, is talking to another

2019-04-20 23:22:21 +0000 edited question Why am I not seeing any interfaces other than USBPcap1 on Windows?

Interface/ New User Hello all. I am new to downloading, installing, and using WireShark. I would like to use it to mon

2019-04-18 04:24:40 +0000 commented answer Tshark capture filter using VLAN ID

Assuming that specifying multiple VLAN IDs and ideally also allowing VLAN ranges with a single vlan option in a captu

2019-04-17 23:26:29 +0000 answered a question How to decode ERSPAN-without-a-header in Wireshark 2.6 and later?

I can correctly see stuff from my source device which encapsulate data to my device So it sounds as if it is dissec

2019-04-17 23:26:29 +0000 received badge  Rapid Responder (source)
2019-04-17 17:54:36 +0000 commented question How to decode ERSPAN-without-a-header in Wireshark 2.6 and later?

All that preference does is to force the ERSPAN dissector to assume the packet doesn't begin with an ERSPAN header. It

2019-04-17 17:51:11 +0000 edited question How to decode ERSPAN-without-a-header in Wireshark 2.6 and later?

Wireshark decode ERSPAN Hello everyone, I'm looking for erspan decoding with my pcap capture. I was doing the classical

2019-04-17 16:56:20 +0000 edited question Can Wireshark decode DIAMETER packets without the IP or transport layer?

Wireshark Packet Decode I wonder if Wireshark can decode the diameter packet without the Transport and IP Layer.

2019-04-16 06:08:28 +0000 commented question Server 2012 R2 Not Capturing Monitor-Session Packets

And were you capturing in promiscuous mode on the port?

2019-04-16 06:08:03 +0000 commented question Server 2012 R2 Not Capturing Monitor-Session Packets

And were you capturing in promiscuous mode on the port? If you're running on a UN*X (Linux, macOS, *BSD, Solaris, etc.)

2019-04-15 20:21:17 +0000 answered a question tshark tmp file not stop growing

Is there any method of pruning the tshark tmp file after the data has been sent to elasticsearch? No. There is, at

2019-04-15 20:21:17 +0000 received badge  Rapid Responder (source)
2019-04-15 20:17:19 +0000 answered a question Are there any plans to add GCP-RPHY decodes?

Plans by whom? There are no plans by the Wireshark core development team to add any dissection for anything; that's lef

2019-04-15 20:17:19 +0000 received badge  Rapid Responder (source)
2019-04-14 04:50:55 +0000 commented answer Why can't I install the latest Wireshark on Windows Server?

If the installer is mis-identifying the platform as Vista... ...then the NSIS code ReadRegStr $R2 HKLM \ "SOFT

2019-04-14 03:23:12 +0000 commented question Why can't I install the latest Wireshark on Windows Server?

And did you get the message Windows Vista is no longer supported. Please install Wireshark 2.2 instead.

2019-04-14 03:22:53 +0000 commented answer Why can't I install the latest Wireshark on Windows Server?

If the installer is mis-identifying the platform as Vista... ...then the NSIS code ReadRegStr $R2 HKLM \ "SOFT

2019-04-14 03:13:39 +0000 commented question Why can't I install the latest Wireshark on Windows Server?

And you got the message Windows Vista is no longer supported. Please install Wireshark 2.2 instead.

2019-04-13 09:41:36 +0000 commented answer tshark capture and filter HTTP in WPA2 secured network

tcpdump syntax is going to mostly be the same as tshark -f capture filter syntax (which are technically both forms of

2019-04-13 09:35:27 +0000 commented answer tshark capture and filter HTTP in WPA2 secured network

I suppose this is the same as wlan host <mac1> or wlan host <mac2>? No. wlan host <mac> checks b

2019-04-13 03:38:50 +0000 answered a question tshark capture and filter HTTP in WPA2 secured network

Capture filters work on raw packets; they're executed either in the kernel (on Linux, *BSD, macOS, Solaris 11, AIX, and

2019-04-13 03:38:50 +0000 received badge  Rapid Responder (source)
2019-04-12 22:52:26 +0000 commented question Why can't I install the latest Wireshark on Windows Server?

On what version of Windows Server are you trying to install it?

2019-04-12 22:50:27 +0000 edited question Why can't I install the latest Wireshark on Windows Server?

Why can't I load latest to windows server?. I get a message saying vista is not supported even though vista is not the o

2019-04-11 22:21:41 +0000 commented answer Tshark capture filter using VLAN ID

If you're doing a live capture on Linux, they wouldn't be equivalent. If you're doing a live capture on any other OS (o

2019-04-11 19:23:39 +0000 answered a question Tshark capture filter using VLAN ID

Is the following one a valid capture filter for VLAN 2001 traffic It's valid, but vlan and ether[14:2]&0x0fff=2

2019-04-11 19:23:39 +0000 received badge  Rapid Responder (source)
2019-04-11 19:18:42 +0000 commented answer Installing and running different versions of Wireshark

Caveat: If this DOCSIS bug is not documented, you should add it to the bug database. ...or it might not get fixed.

2019-04-09 22:38:29 +0000 received badge  Good Answer (source)
2019-04-09 12:23:00 +0000 received badge  Nice Answer (source)
2019-04-09 01:31:20 +0000 answered a question Why are multiple versions released at once

To quote the Development/LifeCycle Wireshark Wiki page: The Wireshark download page lists three types of releases: S

2019-04-09 01:31:20 +0000 received badge  Rapid Responder (source)
2019-04-09 01:25:17 +0000 answered a question Why are there 3 active versions of Wireshark

If you mean "why, for example, were Wireshark 2.4.14, 2.6.8, and 3.0.1 announced on 2019-04-08?", the answer is, to quot

2019-04-09 01:25:17 +0000 received badge  Rapid Responder (source)
2019-04-08 19:37:29 +0000 commented answer MAC Name resolution

But if you put the same entries into a new ethers file in the same directory, it doesn't work?

2019-04-06 20:47:49 +0000 commented question Missing autogen.sh in 3.0.0?

Perhaps the problem is that I am trying to use 2.6 build instructions for 3.0. Yes, that's the problem, as per cmay

2019-04-06 01:50:27 +0000 answered a question Remote capture support for Mac

Does Wireshark provide remote capture support for Mac ? Only if you compile libpcap 1.8 or later (I'd suggest 1.9.0

2019-04-06 01:50:27 +0000 received badge  Rapid Responder (source)
2019-04-05 22:39:39 +0000 edited question won't start a capture 3.0

won't start a capture 3.0 Compiled (64-bit) with Qt 5.12.1, with WinPcap SDK (WpdPack) 4.1.2, with GLib 2.52.2, with zl

2019-04-05 01:10:36 +0000 edited question No interfaces shown

No interfaces shown Installed Wireshark just an hour ago, so I'm really ignorant. Before I can capture traffic I need t

2019-04-04 01:25:25 +0000 edited question Wireshark on macOS not showing full Info column for FCP reassembly errors

Missing data on macOS My pcap file is missing data(error data in the info column) when opened on MacOs. I've tried versi

2019-04-03 21:15:35 +0000 commented question protocol show as UDP instead of SNMP

I tried right click -> decode as ... and looked for SNMP, in the list of Current values, but it isn't there. So

2019-04-03 18:46:31 +0000 commented question Wireshark on macOS not showing full Info column for FCP reassembly errors

And you're using the same version of Wireshark on both machines, and you've set all the preferences for protocols to the

2019-04-03 07:30:51 +0000 edited question Wireshark on macOS not showing full Info column for FCP reassembly errors

Missing data on MAC OS My pcap file is missing data(error data in the info column) when opened on MacOs. I've tried vers

2019-04-03 07:30:35 +0000 commented question Wireshark on macOS not showing full Info column for FCP reassembly errors

What do you mean by "error data in the info column"? What is the exact text displayed in the Info column?

2019-04-03 05:33:05 +0000 commented answer Wireshark does not decode content of NMR field.

p.s. i'd submitted a bug report. That's bug 15665.

2019-04-03 05:32:46 +0000 commented answer Wireshark does not decode content of NMR field.

That's bug 15665.