2023-07-24 18:18:43 +0000 | received badge | ● Notable Question (source) |
2023-03-02 05:11:31 +0000 | commented answer | Capture Filter not working due to incorrect BPF? Thanks Chris! This is great. Two curiosity questions - 1. is there a "runtime" way to tell libpcap NOT to use bpf extens |
2023-03-02 05:08:09 +0000 | commented answer | Capture Filter not working due to incorrect BPF? Yup, the trouble starts only when you open an interface and discover that the socket supports BPF extensions - I think b |
2023-03-01 19:52:42 +0000 | received badge | ● Popular Question (source) |
2023-02-22 05:31:49 +0000 | commented answer | Capture Filter not working due to incorrect BPF? @Chuckc - thanks for updating the link to the libpcap issue here - I forgot to do that. I've seen that FAQ entry, but I |
2023-02-22 05:28:34 +0000 | commented answer | Capture Filter not working due to incorrect BPF? @cmaynard - yes, the Wireshark generated BPF instructions were taken on the same system as dumpcap - an Ubuntu 22.04. Th |
2023-02-21 08:55:57 +0000 | marked best answer | Capture Filter not working due to incorrect BPF? Hi, Wireshark 3.6.2 (Ubuntu 22.04.1 LTS) is not able to capture packets with the below filter -
The packets are UDP with VLAN and have the pattern To investigate, I used All seems ok till we come post the If I'm reading the instructions correctly, I think the problem is (017), (018) which stores Instruction (028) seems incorrect to me as (029) expects x to be 4 similar to (026).
However, the Wireshark Does Wireshark Compile BPFs use a different BPF compiler than dumpcap? Since the instructions generated by dumpcap is same as tcpdump, I assume both of them use the libpcap dumpcap version (more) |
2023-02-21 08:55:57 +0000 | received badge | ● Scholar (source) |
2023-02-21 08:55:27 +0000 | commented answer | Capture Filter not working due to incorrect BPF? Yes, reversing the filter works. The filter is actually part of an application and was written in the form it was to be |
2023-02-20 15:50:21 +0000 | commented question | Capture Filter not working due to incorrect BPF? @Chuckc I've updated dumpcap and tcpdump versions. However, I'm not sure if it's related to the issue you mentioned. |
2023-02-20 15:48:37 +0000 | received badge | ● Editor (source) |
2023-02-20 15:48:37 +0000 | edited question | Capture Filter not working due to incorrect BPF? Capture Filter not working due to incorrect BPF? Hi, Wireshark 3.6.2 (Ubuntu 22.04.1 LTS) is not able to capture packet |
2023-02-20 12:39:26 +0000 | commented question | Capture Filter not working due to incorrect BPF? @jaap - yes, same interface enp0s9 on Wireshark as well. If I remove the or (vlan and icmp) from the filter, packets sta |
2023-02-20 10:26:23 +0000 | asked a question | Capture Filter not working due to incorrect BPF? Capture Filter not working due to incorrect BPF? Hi, Wireshark 3.6.2 (Ubuntu 22.04.1 LTS) is not able to capture packet |