Ask Your Question

Guy Harris's profile - activity

2019-02-15 22:46:09 +0000 commented question Where's the wireless toolbar?

I converted your answer to a comment as it doesn't answer the question as to what happened to the wireless toolbar an

2019-02-15 19:43:17 +0000 commented answer Why is Wireshark displaying "wtap_encap=1" in the Info column?

Hi, Cmaynard, thanks for your contribution. I'm on my own, and nobody touches my PC. So, no practical joke... JJ ..

2019-02-15 19:41:29 +0000 edited question Why is Wireshark displaying "wtap_encap=1" in the Info column?

How do I remove WTAP encapsulation? For the past few days, Wireshark can no longer display packets properly. All od them

2019-02-13 19:35:35 +0000 answered a question Usb-Audio Midi dissector not working properly

It seems like Wireshark is unable to use the right dissector because it is unable to detect that the USB_Bulk message

2019-02-13 19:35:35 +0000 received badge  Rapid Responder (source)
2019-02-13 19:33:48 +0000 commented question USB capture using Wireshark?

So, with an older version of Fedora (before Fedora 29), you used to capture using the usbmon utility and display that wi

2019-02-13 19:30:49 +0000 received badge  Rapid Responder (source)
2019-02-13 19:30:49 +0000 answered a question Wireshark on MacOS Mojave crashes when setting SSL key in protocols

This is probably bug 14453.

2019-02-13 19:27:27 +0000 received badge  Rapid Responder (source)
2019-02-13 19:27:27 +0000 answered a question Why sometimes Wireshark restarts after a profile change?

That's not a feature, as far as I'm concerned. Please file a bug on that on the Wireshark Bugzilla.

2019-02-13 19:25:33 +0000 edited question icmp ttl and total_length are displayed with commas

icmp ttl and total_length are displayed with decimals Hello, I did a capture on my local lan and I see something very we

2019-02-13 03:45:28 +0000 commented question Why sometimes Wireshark restarts after a profile change?

I.e., the answer may be "because the Wireshark developers missed something in the code that handles some settings that c

2019-02-12 23:43:29 +0000 commented question USB capture using Wireshark?

How did you capture USB traffic outside of Wireshark? Was the machine on which you couldn't capture USB traffic within

2019-02-10 16:07:26 +0000 edited answer Traceroute Capture

I just ran C:\Windows\system32>TRACERT.EXE 8.8.8.8 From my older Windows8 box and got this: So it works for me

2019-02-10 16:06:59 +0000 commented answer Traceroute Capture

I am not sure if this is based on a new baseline for the Wireshark. I am not sure if this has anything to do with W

2019-02-10 03:31:58 +0000 commented answer MAC Locally administered address - Resolved names

Devices may use these addresses to obfuscate their identity, to hamper tracking. That's exactly what iOS is doing;

2019-02-10 03:26:04 +0000 commented question Traceroute Capture

I am running traceroute from windows cmd prompt. traceroute, or tracert? UN*X systems tend to ship with traceroute

2019-02-09 23:32:27 +0000 commented question measure the delay and throughput of Wireshrak

In particular, do you want to "measure the delay and throughput of Wireshark", meaning "how many packets per second can

2019-02-08 18:29:57 +0000 commented question How can I parse or convert a .pcapng file?

Note also that any program that uses libpcap to read capture files, such as tcpdump, can read some pcapng files if it's

2019-02-08 18:28:57 +0000 commented question How can I parse or convert a .pcapng file?

As for a download link to TShark, you would get it by downloading and installing Wireshark. We don't have a separate do

2019-02-08 18:26:28 +0000 commented question How can I parse or convert a .pcapng file?

follow-up http://xml2rfc.tools.ietf.org/cgi-bin/xml2rfc.cgi?url=https://raw.githubusercontent.com/pcapng/pcapng/

2019-02-08 18:17:16 +0000 commented question Saving, opening, and viewing a .jpg from an TCP stream over FTP

Wireshark has an "Export Objects" mechanism, which allows data objects transported over various protocols to be written

2019-02-08 18:17:01 +0000 commented question Saving, opening, and viewing a .jpg from an TCP stream over FTP

Wireshark has an "Export Objects" mechanism, which allows data objects transported over various protocols to be written

2019-02-04 22:38:46 +0000 answered a question How to select 3G usb dongle modem as an interface in w. ?

From your other question, you're running on Windows XP. As I explained in the answer to that question, you can't select

2019-02-04 22:36:32 +0000 answered a question How to install Wireshark 2 Preview for Windows XP ?

There was a "Wireshark 2 preview" in the 1.12 Windows installers up to 1.12.1. The name "Wireshark 2 preview" is a bit

2019-02-03 19:44:24 +0000 commented question Upgraded to windows 10, seeing far more accurate & detailed info under "Transport Address"?

What version of Wireshark are you using?

2019-02-01 19:42:06 +0000 received badge  Rapid Responder (source)
2019-02-01 19:42:06 +0000 answered a question 00:00 Source Address 00:00 Destination Address 0x0000 Protocol 342 length

I'd suggest starting with what the answer to the old question says. An OUI of 00:00:00 is assigned to Xerox; that eithe

2019-01-31 08:39:57 +0000 commented answer I need version 1.10.9

@grahamb uninstalled 1.12.1 installed 1.10 for XP reinstalled WinPcap - which generated an error (as below) in the mea

2019-01-31 07:33:20 +0000 commented question How to install Wireshark 2 Preview for Windows XP ?

Which version of Wireshark are they calling "Wireshark 2 Preview"? Wireshark 2.0 was released in November 2015, more th

2019-01-31 07:25:19 +0000 commented question How to select 3G usb dongle modem as an interface in w. ?

Does "w." stand for "Windows" or "Wireshark"? If it stands for "Wireshark", on what operating system are you running Wi

2019-01-30 08:24:50 +0000 commented answer How do I install wireshark legacy on mac?

And you'll need to install an X11 server, such as Xquartz, to use the legacy Wireshark. (That's one reason why we stopp

2019-01-30 08:22:33 +0000 answered a question how to read the summary results in Wireshark 1.12.7

If this is the same as this question, the answer is probably also the same - for one thing, in some locales, including I

2019-01-30 08:22:33 +0000 received badge  Rapid Responder (source)
2019-01-29 20:41:57 +0000 answered a question cara membaca hasil summary di wireshark 1.12.7

how to read the summary results in Wireshark 1.12.7 (Biasanya lebih baik bertanya dalam bahasa Inggris daripada dal

2019-01-29 20:41:57 +0000 received badge  Rapid Responder (source)
2019-01-26 20:14:19 +0000 commented question interface XHC20 does not exist

"can't seem to access the USB ports" as in "I can't capture on them" or as in "I can try to capture on them but no packe

2019-01-25 22:43:46 +0000 commented answer Another filter question

("You" here refers to the person who asked the question.) Note also that, if this network is a "protected" Wi-Fi networ

2019-01-25 20:54:14 +0000 commented answer Can I skip "Finding Local Interfaces"?

I infer from Jasper's answer that the service is "npf" for WinPcap and "npcap" for Npcap; you used "npf", so I'm inferri

2019-01-25 20:25:02 +0000 commented answer Can I skip "Finding Local Interfaces"?

I just launched Wireshark after my laptop was rebooted, and the launch time has shrunk significantly. I was wonderi

2019-01-25 00:03:26 +0000 commented answer Can I skip "Finding Local Interfaces"?

As it turns out, C:\Program Files\Wireshark\extcap exists, but is EMPTY. You probably didn't install the extcap pro

2019-01-24 21:45:28 +0000 commented answer Can I skip "Finding Local Interfaces"?

Your problem might be with extcap. Jasper's problem is with *pcap. As this is Windows, Wireshark is probably installed

2019-01-24 18:14:59 +0000 commented answer Can I skip "Finding Local Interfaces"?

Note that, as per bug 15126, there are two parts to "Finding local interfaces" - there's finding the interfaces that lib

2019-01-24 10:17:03 +0000 answered a question When I try and use the "ip broadcast" capture filter it says "netmask not known, so 'ip broadcast' not supported"?

"ip broadcast" means "the destination IP address is a broadcast address". As RFC 922 indicates, there are multiple type

2019-01-24 10:17:03 +0000 received badge  Rapid Responder (source)
2019-01-24 05:39:50 +0000 commented answer How to insert network key when use tshark in command line

It might be possible to set it with the -o flag, but we don't have very good documentation on setting preferences in gen

2019-01-24 05:12:36 +0000 commented question how can find specifiction of a unknown network X

Those are mostly properties of an asynchronous serial line; a protocol running on an asynchronous serial line might spec

2019-01-22 08:57:01 +0000 answered a question no packets captured in monitor mode

This may be a bug in the Mojave driver; at least some MacBooks have problems with monitor mode in Mojave. File a bug wi

2019-01-22 08:57:01 +0000 received badge  Rapid Responder (source)
2019-01-22 01:20:30 +0000 received badge  Rapid Responder (source)