Ask Your Question

Guy Harris's profile - activity

2021-02-28 22:52:04 +0000 commented answer Add vsa defination for pfcp packet without compiling wireshark?

In particular, read the very first word of the answer.

2021-02-28 06:54:04 +0000 edited question Wireshark doesn't ask what connection (Ethernet, Wi-Fi, etc.) I'm on when it starts up

dont show up pleas help hi wireshark when i turn on my wireshARK it doest ask my on what connection i am for example et

2021-02-28 01:28:48 +0000 received badge  Rapid Responder (source)
2021-02-28 01:28:48 +0000 answered a question Wireshark doesn't ask what connection (Ethernet, Wi-Fi, etc.) I'm on when it starts up

It's not supposed to ask. Instead, it finds out, from the operating system, what network interfaces you have, and lets

2021-02-28 01:28:44 +0000 edited question Wireshark doesn't ask what connection (Ethernet, Wi-Fi, etc.) I'm on when it starts up

dont show up pleas help hi wireshark when i turn on my wireshARK it doest ask my on what connection i am for example et

2021-02-26 05:52:51 +0000 answered a question IEEE802a OUI Extended Ethertype

IEEE 802a is now section 9.2.4 "OUI Extended EtherType" of IEEE 802-2014. It's a way to provide the same capabilities a

2021-02-26 05:52:51 +0000 received badge  Rapid Responder (source)
2021-02-24 01:34:46 +0000 edited question How to install Npcap for wireshark on a galaxy S book with a 64-bit ARM that emulates a 32 bit x86 processor?

How to install the ncap for wireshark on a galaxy S book with a 64-bit ARM that emulates a 32 bit x86 processor? I am un

2021-02-23 08:26:29 +0000 received badge  Rapid Responder (source)
2021-02-23 08:26:29 +0000 answered a question How to install Npcap for wireshark on a galaxy S book with a 64-bit ARM that emulates a 32 bit x86 processor?

Npcap currently doesn't support Windows-on-ARM; that's issue #57 on the Npcap issue list. (It includes a kernel-mode dr

2021-02-21 06:03:14 +0000 commented question Wireshark will not download on a windows 10. We tried the solutions on some of the web sites. What can we do?

This isn't a forum, it's a Q&A site; think of it as a "crowdsourced FAQ". The relevant information should be public

2021-02-19 12:47:33 +0000 commented answer Internet ethernet not working until starting capture on win10

Please mention that somewhere in a relevant Npcap issue.

2021-02-19 09:21:04 +0000 received badge  Rapid Responder
2021-02-19 09:21:04 +0000 answered a question Building on Debian 10 - gcrypt not found?

Hit:1 http://deb.debian.org/debian buster InRelease Hit:2 https://packages.microsoft.com/debian/10/prod buster InReleas

2021-02-19 09:12:49 +0000 answered a question Internet ethernet not working until starting capture on win10

This appears to be Npcap issue #221. Report details there.

2021-02-19 09:12:49 +0000 received badge  Rapid Responder (source)
2021-02-19 09:08:07 +0000 edited question No HTTPS requests in a TCP stream? (also decoding-help)

No HTTP requests in a TCP stream? (also decoding-help) So I am having an issue where I am not able to see the actual HTT

2021-02-17 05:02:43 +0000 answered a question problem getting traffic on wifi network between smartphone and printer on a Mac- monitor mode problem

my new MacBook Air There's your problem. the en0 set with promiscuous mode and monitor mode checked, I see noth

2021-02-17 05:02:43 +0000 received badge  Rapid Responder (source)
2021-02-16 22:23:50 +0000 edited question Where can I download source code for DECT dissectors from Dosch and Amand?

Where can I download source code ? DECT dissector for DECT Catiq is available in this product http://www.ezutech.com/D

2021-02-16 22:22:44 +0000 commented answer Where can I download source code for DECT dissectors from Dosch and Amand?

And, given that Wireshark is provided under the GPL, add-on dissectors must also be licensed under the GPL, and thus mus

2021-02-13 07:26:03 +0000 commented question colorization isn't working

So all packets have the default color? I tried it on my 11.2.1 VM, with a default installation of 3.4.3, and it does co

2021-02-13 07:10:45 +0000 edited question colorization isn't working

colorization isn't working MacOS 11.2.1 On WS version 3.4.3 (v3.4.3-0-g6ae6cd335aa9) colorization of any packets isn't w

2021-02-13 07:05:49 +0000 commented answer Is it possible to load an xml file to a custom plugin c dissector?

I hope its okay to ask a second question here. It's best to ask each question separately. This is a Q&A site,

2021-02-10 05:21:11 +0000 commented question BPF permission denied when not connected to an OpenVPN connection

So what happens if, when you're not connected to a VPN, you run the command sudo dseditgroup -q -o edit -a {your user n

2021-02-09 04:27:48 +0000 commented question BPF permission denied when not connected to an OpenVPN connection

What does the command dscl . -read /Groups/access_bpf print?

2021-02-08 19:35:49 +0000 commented question tshark: This version of TShark was not built with support for capturing packets.

After building libpcap, did you run make install in its source directory, as root? If you want Wireshark to be built wi

2021-02-08 01:14:14 +0000 commented question BPF permission denied when not connected to an OpenVPN connection

Now that it's working, does the access_bpf group show up in System Preferences > Users and Groups?

2021-02-05 01:40:38 +0000 commented question unusually many accesses banned from google how??

unusually many access trys Meaning "too many Google searches" or "too many failed attempts to log into your Google

2021-02-02 21:14:57 +0000 answered a question Blue Screen while saving 1-hour capture

That's either a crashing bug in Npcap (or WinPcap) or in Windows itself. My guess is the latter, because it crashed aft

2021-02-02 21:14:57 +0000 received badge  Rapid Responder (source)
2021-02-02 06:32:59 +0000 commented question eapol is malformed unless I assume don't have FCS but then all other packets are malformed

Monitor mode capturing on Windows is, in some areas, a big ball of pain. For one thing, drivers don't do a good job of

2021-02-02 03:06:38 +0000 commented answer select a dissector by magic in header

@Chuckc: I don't know whether everybody's allowed to do this, but there's a "convert to answer" link below a comment, af

2021-02-02 03:02:18 +0000 commented question eapol is malformed unless I assume don't have FCS but then all other packets are malformed

On what operating system are you capturing this?

2021-01-29 21:51:20 +0000 edited answer How to filter packets with BPF in a C++ program when they're not read from a live capture or pcap/pcap-ng file?

(This is really a libpcap question, but....) The packets are always VLAN encapsulated. That means that all filters

2021-01-29 21:50:47 +0000 answered a question How to filter packets with BPF in a C++ program when they're not read from a live capture or pcap/pcap-ng file?

(This is really a libpcap question, but....) The packets are always VLAN encapsulated. That means that all filters

2021-01-29 21:50:47 +0000 received badge  Rapid Responder (source)
2021-01-29 20:05:00 +0000 answered a question Get 802.11 frames while associated with network

As the new MacBook still uses the AirPort Extreme there should be a solution? Perhaps you want there to be a soluti

2021-01-29 20:05:00 +0000 received badge  Rapid Responder (source)
2021-01-27 03:00:39 +0000 commented question tshark strange behavior with capture filter

So the first 14 bytes of the packet are XX XX XX XX XX XX XX XX XX XX XX XX 08 00, with the XX's being the destination a

2021-01-27 02:46:35 +0000 commented answer Wireshark Setup for 802.11ax association requests

afaik there is no "native" Wireshark version for the M1 processor. Not yet - we'll need either to do a cross-build

2021-01-27 02:04:43 +0000 commented question No AVDTP in Bluetooth HCI trace with LDAC audio

Would it be possible to confirm if we havefull BLE decoding support in recent Wireshark versions? Yes, it would be

2021-01-25 04:32:51 +0000 commented question Wireshark Hanging/Not launching

On what operating system is this? What version of Wireshark were you using?

2021-01-21 19:26:53 +0000 commented question tshark strange behavior with capture filter

But please have a look on the edit. That gives no additional information. At this point, I need to see at least s

2021-01-21 07:16:56 +0000 commented question tshark strange behavior with capture filter

Can you show Wireshark's detailed dissection of one of those packets? You don't need to show anything after the UDP lay

2021-01-21 07:14:48 +0000 commented question Wireshark not recognizing Wi-Fi Adapter

On what operating system is this? And on what version of that operating system?

2021-01-21 04:28:01 +0000 commented question tshark strange behavior with capture filter

So if you capture without a filter, you see traffic to and from port 30000, but if you capture with "port 30000", you do

2021-01-21 04:25:59 +0000 commented question keep getting malformed packet docsis

So you're just capturing on an Ethernet or Wi-Fi interface, and you're just capturing at your home or at your office (an

2021-01-20 07:56:31 +0000 edited question wireshark io graph can't show some parameters in Y field

wireshark io graph can't show some parameters in Y field hi One parameter in Y Field (set MAX Y Field)can't be displaye

2021-01-20 03:30:13 +0000 commented question Unable to see SMTP traffic after getting new laptop

So are you capturing on Ethernet or on Wi-Fi? From "when using a HUB or Port mirrored switch" it sounds as if it'd be E