Ask Your Question

SJZK's profile - activity

2023-07-15 19:00:27 +0000 received badge  Famous Question (source)
2023-07-15 19:00:27 +0000 received badge  Notable Question (source)
2021-08-07 01:29:05 +0000 received badge  Popular Question (source)
2019-03-15 16:25:01 +0000 asked a question tshark - How can I specify a tab as the -E aggregator character? /s becomes a space, but /t becomes a forward slash, a keyboard tab generates a syntax error.

tshark - How can I specify a tab as the -E aggregator character? /s becomes a space, but /t becomes a forward slash, a k

2019-01-29 21:44:53 +0000 commented question Timestamp values from VMHOST likely moved by VMotion

I believe they downloaded the standard Wireshark install which would have loaded WinPcap. Looking through my old files w

2019-01-29 20:10:40 +0000 asked a question Timestamp values from VMHOST likely moved by VMotion

Timestamp values from VMHOST likely moved by VMotion I have two capture files of the same traffic between a pair of Wind

2018-11-14 15:17:41 +0000 commented answer why does Wireshark flag the retransmission of a single byte fragment as a keep-alive? A true keep-[alive is an ACK with no data, tcp.len==0.

can't provide the actual trace, but here is a summary of the packets of interest: Time Delta-Time Info

2018-11-14 15:17:03 +0000 commented answer why does Wireshark flag the retransmission of a single byte fragment as a keep-alive? A true keep-[alive is an ACK with no data, tcp.len==0.

can't provide the actual trace, but here is a summary of the packets of interest: Time Delta-Time Info

2018-11-13 20:56:31 +0000 commented answer why does Wireshark flag the retransmission of a single byte fragment as a keep-alive? A true keep-[alive is an ACK with no data, tcp.len==0.

Unfortunately, the 1 byte in the "keep-alive"s is the actual 1 byte fragment, and the keep-alives are really retransmiss

2018-11-13 17:58:09 +0000 asked a question why does Wireshark flag the retransmission of a single byte fragment as a keep-alive? A true keep-[alive is an ACK with no data, tcp.len==0.

why does Wireshark flag the retransmission of a single byte fragment as a keep-alive? A true keep-[alive is an ACK with