Ask Your Question

cmaynard's profile - activity

2020-11-25 18:20:51 +0000 commented answer Promiscuous mode and switch

Jasper Bongertz also wrote a very good blog article about SPAN ports titled, The Network Capture Playbook Part 4 – SPAN

2020-11-25 01:46:47 +0000 edited question How to create multi-layer Lua dissector?

How to create multi-layer Lua dissector? I have several UDP protocols with same 12-bytes header. I have read blog: http

2020-11-25 01:36:27 +0000 edited question How to create multi-layer Lua dissector?

How to create multi-layer Lua dissector? I have several UDP protocols with same 12-bytes header. I have read blog: http

2020-10-26 20:07:51 +0000 edited answer wireshark lua for a new ethernet header

The problem seems to be that packet-ethertype.c:dissect_ethertype() expects to be passed a pointer to an ethertype_data_

2020-10-26 19:58:02 +0000 received badge  Rapid Responder (source)
2020-10-26 19:58:02 +0000 answered a question wireshark lua for a new ethernet header

The problem seems to be that packet-ethertype.c:dissect_ethertype() expects to be passed a pointer to an ethertype_data_

2020-10-24 14:18:57 +0000 edited question After several hours of operation on Windows 10, wireshark stops with "The network adapter on which the capture was being done is no longer running"

Al cabo de varias horas de funcionamiento , wireshark se para Deja de funcionar. Si lo paro y vuelvo a arrancar funciona

2020-10-23 17:21:55 +0000 commented question Lua: populate a field from DissectorTable

Actually, it seems pinfo.private isn't read-only at all. I guess I don't understand what affect WSLUA_ATTRIBUTE_ROREG()

2020-10-23 15:40:28 +0000 commented question Lua: populate a field from DissectorTable

I think I understand now. I'm not sure how you could get the name from the proto; however, it might be possible to do s

2020-10-23 15:39:00 +0000 commented question Lua: populate a field from DissectorTable

I think I understand now. I'm not sure how you could get the name from the proto; however, it might be possible to do s

2020-10-23 04:15:31 +0000 commented question Lua: populate a field from DissectorTable

I'm struggling to understand exactly what you're hoping to do. Could you elaborate a bit more and maybe even provide so

2020-10-16 16:00:50 +0000 commented answer Is there a simple LUA script as an example for simple pcaps?

I'm not sure what new information is presented here that isn't already included in the Wireshark Developer's Guide, incl

2020-10-16 15:47:28 +0000 commented answer How do you pass arguments to subdissectors in Lua?

I think @stig's answer is the best one for sending data from one Lua dissector to another and it doesn't require that th

2020-10-16 15:41:16 +0000 edited question How do you pass arguments to subdissectors in Lua?

How do you pass arguments to subdissectors in Lua? I have one Lua dissector that calls a subdissector, as so: second_di

2020-09-30 18:44:44 +0000 edited answer capture TCP/IP data

Yes, you can capture the data if your capture setup allows you to do so, and you can decode the data if Wireshark suppor

2020-09-30 18:42:23 +0000 answered a question capture TCP/IP data

Yes, you can capture the data if your capture setup allows you to do so, and you can decode the data if Wireshark suppor

2020-09-30 18:42:23 +0000 received badge  Rapid Responder (source)
2020-09-30 00:43:01 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

Although I am now old enough to join AARP, I'm not responding as a senior member; I consider us all peers as we're all i

2020-09-30 00:36:35 +0000 answered a question preserve source file info when merging

After merging .pcapng files into another .pcapng file, you ought to be able to determine the file from which the packets

2020-09-30 00:36:35 +0000 received badge  Rapid Responder (source)
2020-09-29 15:29:13 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

Yes, I was working with the global dfilters file. I repeated the process with a profile dfilters file, but the behavior

2020-09-29 15:00:44 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

NOTE: You don't actually have to add any new display filters to see the extra carriage return added, as merely clicking

2020-09-29 14:54:28 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

So I see the extra carriage return, but the steps to reproduce it seem to be: Copy/paste dfilters_sample.txt contents

2020-09-29 14:37:28 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

I appended the dfilters_sampe.txt contents to the default dfilters file, and everything looks fine, but I am still using

2020-09-29 13:59:13 +0000 commented question Lab 23 is not displaying as expected in the bookmark filters menu. Could it be because there is a difference with the new version of Wireshark?

Where is this dfilters_sample.txt file?

2020-09-28 19:39:50 +0000 answered a question How to get the raw bytes of a data link address in lua dissector pinfo (pinfo.dl_src or pinfo.dl_dst)?

I don't think this is possible using pinfo.dl_src and pinfo.dl_dst. Even if you disable MAC address name resolution, th

2020-09-16 14:50:52 +0000 received badge  Rapid Responder (source)
2020-09-16 14:50:52 +0000 answered a question See Ethernet device and track it

There are several methods available for capturing Ethernet traffic. Refer to the Wireshark Ethernet capture setup wiki

2020-09-16 14:49:37 +0000 edited question See Ethernet device and track it

See ethernet device and track it I have a device plugged into the ethernet of my router. It's a Comrex Axxess that allow

2020-09-15 16:33:45 +0000 commented question Why can't wireshark capture HTTP packets

If you're trying to capture HTTP packets to/from your own device, then you should be able to achieve that without a prob

2020-09-11 04:53:37 +0000 answered a question Can I read rearranged nibbles across bytes as a single value from lua

Judging by the "Want to read a value as ..." comment where 0 512 88 was desired, it looks to me like you have 3 differen

2020-09-11 04:53:37 +0000 received badge  Rapid Responder (source)
2020-09-11 04:16:00 +0000 commented question Can I read rearranged nibbles across bytes as a single value from lua

There would seem to be a typo as 0 512 88 would be 0x00 0x02 0x00 0x58 and not 0x00 0x20 0x00 0x58. Is that what was in

2020-09-09 16:45:33 +0000 commented answer NTPv4 Autokey protocol: pcap does not meet the standard

It is currently supported as of this writing in the stable releases, albeit with bugs.

2020-09-09 16:43:07 +0000 commented question Decoding a TZSP stream

Can you post a sample capture file?

2020-09-09 16:34:49 +0000 commented answer NTPv4 Autokey protocol: pcap does not meet the standard

"The NTP dissector doesn't currently perform any dissection of Extension fields" This isn't true, at least not prior to

2020-09-09 16:23:36 +0000 commented answer NTPv4 Autokey protocol: pcap does not meet the standard

"The NTP dissector doesn't currently perform any dissection of Extension fields" This isn't true, at least not prior to

2020-09-09 15:46:21 +0000 edited answer NTPv4 Autokey protocol: pcap does not meet the standard

Your capture doesn't seem to comply with the RFC, that field type value (0x0201) isn't on the IANA list. The NTP dissec

2020-09-09 15:46:06 +0000 edited answer NTPv4 Autokey protocol: pcap does not meet the standard

Your capture doesn't seem to comply with the RFC, that field type value (0x0201) isn't on the IANA list. The NTP dissec

2020-09-06 15:29:37 +0000 commented question lua dissector absolute time

So which, if any, of the encodings listed at https://gitlab.com/wireshark/wireshark/-/blob/master/doc/README.dissector#L

2020-09-06 15:29:16 +0000 commented question lua dissector absolute time

So which, if any, of the encodings listed at https://gitlab.com/wireshark/wireshark/-/blob/master/doc/README.dissector#L

2020-09-03 19:52:52 +0000 received badge  Rapid Responder (source)
2020-09-03 19:52:52 +0000 answered a question Help needed with DissectorTable

I don't know how to do #1, "Pass PayloadLength to the lower level dissector", but to do #2, I think you can just generat

2020-09-01 16:28:32 +0000 answered a question Lua - Get hex value of a field

While the original answer I provided does work, I've since realized there's a much simpler solution. Instead of working

2020-08-27 06:47:49 +0000 commented answer Why are all remote MAC addresses HonHaiPr_85:c9:be (94:39:e5:85:c9:be)

This is the complete information from a packet which was going to google: That packet was not going to Google, at least

2020-08-27 06:47:23 +0000 commented answer Why are all remote MAC addresses HonHaiPr_85:c9:be (94:39:e5:85:c9:be)

This is the complete information from a packet which was going to google: That packet was not going to Google, at least

2020-08-27 06:35:09 +0000 commented answer Why are all remote MAC addresses HonHaiPr_85:c9:be (94:39:e5:85:c9:be)

Thank you. I thought Wireshark was supposed to pick up the remote host's MAC address. This is the complete information

2020-08-26 16:16:06 +0000 received badge  Rapid Responder (source)
2020-08-26 16:16:06 +0000 answered a question Why are all remote MAC addresses HonHaiPr_85:c9:be (94:39:e5:85:c9:be)

As @grahamb mentioned, the MAC address could belong to the gateway, but if you want to know what IP address is associate

2020-08-25 20:01:47 +0000 commented answer Trying to Understand Protocol Hierarchy Statistics

Would Statistics->Conversations or Statistics->Endpoints be better for this data? I would say yes. There are som