Ask Your Question

cmaynard's profile - activity

2021-08-24 15:51:25 +0000 answered a question How to save in a variable a specific value from masked bytes?

Ideally you could accomplish this as follows: local Year_proto = ProtoField.uint16("Variable_Year", "This is the transm

2021-08-24 15:37:29 +0000 commented question How to save in a variable a specific value from masked bytes?

OK, so the bitfield is split across a multi-byte field, which is transmitted in Little-Endian format but the 7 bits that

2021-08-23 14:50:48 +0000 commented question Network data stealing by someone

Can you please help me figure out what is wrong. To be blunt: what's wrong here is giving out the WiFi password. Only gi

2021-08-23 14:49:52 +0000 commented question Restrict Wireshark to GNS3 on host computer?

I'm not aware of any method to restrict Wireshark's capture capability to only GNS3. If a capture library/driver (e.g.,

2021-08-23 14:43:51 +0000 edited question Is there a plug-in showing MPLS statistics?

Is there a plug-in showing MPLS statistis? Hello, Is there a plug-in for Wireshark which can show MPLS statistics? For i

2021-08-23 14:39:52 +0000 commented question How to save in a variable a specific value from masked bytes?

What do you mean by LITTLE-ENDIAN 7 bits number? You mentioned that, "The bit mask should be 0x07f0 = 0000 0111 1111 00

2021-08-12 11:28:39 +0000 edited answer Lua vlan tag value extraction

The VLAN Display Filter Reference page lists several VLAN-related fields. You can access any of them from your Lua diss

2021-08-11 12:35:33 +0000 answered a question Lua vlan tag value extraction

The VLAN Display Filter Reference page lists several VLAN-related fields. You can access any of them from your Lua diss

2021-08-11 12:35:33 +0000 received badge  Rapid Responder (source)
2021-08-10 13:00:15 +0000 commented question I am getting an error while running tcprewrite --seed 216 --infile '' --outfile '' on this pcap. I have checked with other pcaps and it's working fine with them. Can somebody check what could be possibly wrong with the pcap?

This is a question for tcpreplay, not Wireshark. Here's their support page: https://tcpreplay.appneta.com/wiki/support.

2021-08-05 19:41:03 +0000 commented answer LUA: avoid auto-expand sub-tree

Yes, either that or a table of functions per TLV type and within each function, the appropriate ProtoField would be used

2021-08-05 19:38:23 +0000 commented answer I wanna hook up Wireshark to my Xbox. How?

I think @ALT should spend some time trying anyway. I mean, it's fruitless but at least there's a chance of learning som

2021-08-05 19:24:10 +0000 commented answer LUA: avoid auto-expand sub-tree

It doesn't necessarily have to be a messy nested "if then else"; you could grab the type from the TLV then use it to add

2021-08-05 18:57:03 +0000 answered a question I wanna hook up Wireshark to my Xbox. How?

You can refer to the CaptureSetup wiki page for help in setting up Wireshark to capture packets. And no, I will not use

2021-08-05 18:57:03 +0000 received badge  Rapid Responder (source)
2021-08-05 18:48:30 +0000 commented answer LUA: avoid auto-expand sub-tree

I don't know how many different TLV types you have to be concerned with, but if it's not a large number, you could decla

2021-08-05 17:30:41 +0000 received badge  Rapid Responder (source)
2021-08-05 17:30:41 +0000 answered a question LUA: avoid auto-expand sub-tree

I suspect this is because of the reuse of same ProtoField during the walk-in iteration. Yes, that's the reason. Otherw

2021-08-05 16:03:22 +0000 received badge  Rapid Responder (source)
2021-08-05 16:03:22 +0000 answered a question How can I read a Buffer in a Little Endian order?

As I mentioned in the comment to this question, the answer is: subtree:add_le(somefield, buffer(94, 2), buffer(94, 2):l

2021-08-04 19:58:04 +0000 commented answer How to get 20 of 24 bits in a LITTLE-ENDIAN Coding?

In that case, you should be able to use something like this: subtree:add_le(somefield, buffer(94, 2), buffer(94, 2):le

2021-08-04 19:56:59 +0000 commented answer How to get 20 of 24 bits in a LITTLE-ENDIAN Coding?

In that case, you should be able to use something like this: subtree:add_le(somefield, buffer(94, 2), buffer(94, 2):le

2021-08-04 19:56:26 +0000 commented answer How to get 20 of 24 bits in a LITTLE-ENDIAN Coding?

In that case, you should be able to use something like this: subtree:add_le(somefield, buffer(94, 2), buffer(94:2):le_

2021-08-02 16:29:47 +0000 received badge  Rapid Responder (source)
2021-08-02 16:29:47 +0000 answered a question How to get 20 of 24 bits in a LITTLE-ENDIAN Coding?

First, it doesn't look like you're calling subtree:add_le() correctly, because the first argument should be a protofield

2021-08-02 16:24:59 +0000 edited question How to get 20 of 24 bits in a LITTLE-ENDIAN Coding?

How to get 20 of 24 bits in a LITTLE-ENDIAN Coding? I am writing my LUA-Code in order to decode a UDP-Payload. I need to

2021-08-01 23:56:31 +0000 edited answer LUA: tlv_tree:add "hex data sequence"

I think there's an even easier way to achieve the same results using something like this: f.data = ProtoField.bytes("S8

2021-08-01 23:54:37 +0000 answered a question LUA: tlv_tree:add "hex data sequence"

I think there's an even easier way to achieve the same results using something like this: f.data = ProtoField.bytes("S8

2021-07-29 14:18:42 +0000 commented question Need help with some ethernet issue.. does that look normal ?

Need help with some ethernet issue What is the Ethernet issue you're experiencing? does that look normal ? Yes, it lo

2021-07-29 14:18:25 +0000 commented question Need help with some ethernet issue.. does that look normal ?

Need help with some ethernet issue What is the Ethernet issue you're experiencing? does that look normal ? Yes, it look

2021-07-28 22:06:09 +0000 commented answer help with LUA + ipv4 + append_text

To eliminate the "TLV Value: " prefix from being displayed, you can try this: tlv_tree:append_text ("," .. string.sub(t

2021-07-28 16:43:13 +0000 answered a question help with LUA + ipv4 + append_text

There are at least 2 ways to achieve this. Use treeitem.text. For example: local ti = tlv_tree:add (f.tlvvalue_ipv4,

2021-07-28 16:43:13 +0000 received badge  Rapid Responder (source)
2021-07-08 22:13:44 +0000 answered a question Still can't turn off auto-updates

Preferences are applicable per-profile, so if you had changed profiles then it's certainly possible that the gui.update.

2021-07-08 22:13:44 +0000 received badge  Rapid Responder (source)
2021-06-29 15:11:30 +0000 edited answer Does this site support pre-moderation?

Yes, it does and as of June 28, 2021, it is now configured for pre-moderation to prevent spammers from posting their non

2021-06-29 15:07:58 +0000 edited answer Does this site support pre-moderation?

Yes, it does and as of June 28, 2021, it is now configured for pre-moderation to prevent spammers from posting their non

2021-06-29 12:57:45 +0000 received badge  Rapid Responder (source)
2021-06-29 12:57:45 +0000 answered a question Does this site support pre-moderation?

Yes, it does and as of June 28, 2021, it is now configured for pre-moderation to prevent spammers from posting their non

2021-06-27 14:55:02 +0000 edited question UDP Port 889 Broadcast (ip.ttl "Time to Live" only 1)

UDP Port 889 Broadcast (ip.ttl "Time to Live" only 1) I found packets like this on my home LAN. A Google search "udp por

2021-06-27 14:51:30 +0000 edited answer AskBot - revision history similar to Bugzilla (bugs.wireshark.org)

Maybe the revision history doesn't show tag updates? I feel kinda like DenverCoder9 - so close. :-)

2021-06-27 14:38:43 +0000 commented answer IPv4 Statistics -> IP Protocol Types

Personally, I think an enhancement bug should be opened for this behavior. First off, if all other protocol types besid

2021-06-24 14:28:57 +0000 commented question Not able to see client certificate in capture

As @grahamb stated, it's difficult to say without more information, but if I were to guess, I'd say it's likely that the

2021-06-24 14:23:23 +0000 commented answer How should I correctly use "Resolving names"?

Statistics -> Conversations is similarly affected regarding the state of the Name resolution checkbox.

2021-06-24 13:59:38 +0000 commented answer How should I correctly use "Resolving names"?

Yes, but ... after 1-2 seconds a tick from the box disappears That sounds like a bug to me, one that could be reported

2021-06-24 13:51:00 +0000 edited question Intermittent Network Slowness/Complete loss of Connectivity

Intermittent Network Slowness/Complete loss of Connectivity I have a network stood up with vSphere. Over the past coupl

2021-06-16 14:47:12 +0000 commented question Why 40 bytes overhead at end of TCP/IP Frames?

same sample data frame Are you sure they're the same? The bytes preceding the data bytes in italics are different, so

2021-06-07 20:51:45 +0000 edited answer CMake problems with building with with Qt 6 on Windows

set QT5_BASE_DIR=C:\Qt\6.1.0\msvc2019_64 I don't think Wireshark works with Qt 6 yet. Please try with Qt 5.15.2. And

2021-06-07 20:51:39 +0000 edited question CMake problems with building with with Qt 6 on Windows

new build issues I was following the step by step guide (https://www.wireshark.org/docs/wsdg_html_chunked/ChSetupWin32.h

2021-06-07 20:49:20 +0000 edited question CMake problems with building with with Qt 6 on Windows

new install issues I was following the step by step guide (https://www.wireshark.org/docs/wsdg_html_chunked/ChSetupWin32