Ask Your Question

grahamb's profile - activity

2024-04-19 07:42:53 +0000 commented question very tiny text

The OS you're using would help. Works fine for me on a 4k 43" monitor on Windows 10 with the Wireshark preferences font

2024-04-18 15:40:36 +0000 commented question How to find RTP packetiztion time (ptime)

1.8.15 is an extremely old version of Wireshark and there have been many, many changes since then.You should upgrade to

2024-04-16 14:53:46 +0000 edited question TCP Port numbers reused

TCP Port numbers reused Hi experts, For the pcap, SYN、SYN/ACK、RST、SYN、SYN/ACK、RST, When I ignore the No.4 SYN packet,Wh

2024-04-16 14:36:33 +0000 edited question TCP Port numbers reused

TCP Port numbers reused Hi experts, For the pcap, SYN、SYN/ACK、RST、SYN、SYN/ACK、RST, When I ignore the No.4 SYN packet,Wh

2024-04-16 08:04:57 +0000 commented question Why would wireshark on one PC capture LLDP packets and another not?

Also Wireshark profiles may be different on the two instances.

2024-04-15 09:04:58 +0000 edited question Custom ecpri dissector based on original implementation

Custom ecpri dissector based on original implementation Hello, I need some modification to basic epan/dissectors/packet

2024-04-12 13:18:36 +0000 commented question Update offline

Can't you manage updates through whatever other automation solution you have, e.g. for OS updates?

2024-04-12 08:48:24 +0000 commented question bitbake wireshark 4.2.3

Duplicate of https://ask.wireshark.org/question/34126/bitbake-wireshark-423-stuck-at-99/

2024-04-09 18:33:26 +0000 commented question visual c++ redistributable installer failed with error 5

Mostly this issue comes up when systems are too old or are not up to date with MS updates and a pre-requisite is missing

2024-04-09 07:23:12 +0000 edited answer Could tshark capture the de-encrypted packet when receiving ESP?

Seems expected for tunnel mode, from code of kernel. xfrm_input .... if (x->outer_mode->flags & XFRM_MODE

2024-04-03 07:48:13 +0000 received badge  Rapid Responder (source)
2024-04-03 07:48:13 +0000 answered a question I am not able to capture TCP data packets from a specific IP

Probably your capture setup doesn't permit the capture of the required info. This is particularly likely if your enviro

2024-04-01 07:26:09 +0000 commented answer bitbake wireshark 4.2.3 stuck at 99%

This is not a Wireshark project issue, BitBake is not a supported build system. I have no experience whatsoever with Bit

2024-03-28 08:55:42 +0000 received badge  Rapid Responder (source)
2024-03-28 08:55:42 +0000 answered a question bitbake wireshark 4.2.3 stuck at 99%

That looks like a question for the BitBake folks, or the producer of the recipe for the Wireshark build.

2024-03-25 08:56:52 +0000 answered a question Wireshark dependency on minimum/specific npcap/winpcap versions?

Winpcap is dead, although Wireshark is able to use it if it's the only capture library available, this isn't recommended

2024-03-25 08:56:52 +0000 received badge  Rapid Responder (source)
2024-03-20 13:55:43 +0000 answered a question Monitor Mode in MacOS Sonoma

Maybe the OSX section of the WLAN Capture Setup wiki page will help.

2024-03-20 13:55:43 +0000 received badge  Rapid Responder (source)
2024-03-14 08:54:48 +0000 edited question ERROR MESSAGE WHEN STOPPING/RESTARTING CAPTURE

ERROR MESSAGE WHEN STOPPING/RESTARTING CAPTURE I receive the following error message when stopping the capture: Error f

2024-03-13 17:24:02 +0000 answered a question WiresharkPortable64_4.2.3.paf.exe has all the functionality?

It does not have the same functionality as the npcap installer isn't included so you won't be able to capture traffic.

2024-03-13 17:24:02 +0000 received badge  Rapid Responder (source)
2024-03-13 17:10:52 +0000 commented question POST Request to API with Wireshark

Don't scrape text from the dialog, use the "Copy to Clipboard" button. One of my best ever contributions to the project

2024-03-12 09:43:01 +0000 commented question How should I share code when I lack the karma to attach it?

E.g. a public file share. Unfortunately this is required otherwise spammers will abuse the "free" upload option. Karma

2024-03-12 09:42:06 +0000 commented question How should I share code when I lack the karma to attach it?

E.g. a public file share. Unfortunately this is required otherwise spammers will abuse the "free" upload option.

2024-03-12 09:41:43 +0000 commented question I have malformed packets observed in my bacnet MSTP protocol, can you able to sight a reason why those are formed?

Captures can be uploaded to a public file share and a link to the file posted back here. Unfortunately this is required

2024-03-12 09:39:43 +0000 commented question How should I share code when I lack the karma to attach it?

E.g. a public file share.

2024-03-08 14:40:04 +0000 edited question "unable to set channel or offset" when switching WiFi channels

"unable to ste channel or offset" when switching WiFi channels Hi, When I switch from channel 1 to another channel (e.g

2024-02-29 18:10:44 +0000 commented question Installing wireshark/tshark on Linux Debian

Heading a long way out of my comfort zone, I think you add the PPA to your apt sources, apt update and then the newer ve

2024-02-29 17:48:35 +0000 commented question Installing wireshark/tshark on Linux Debian

A core developer does provide up to date builds for Debian and Ubuntu but I don't know any more than that. For Ubuntu s

2024-02-28 17:14:17 +0000 commented question Available ports on a switch

Not a Wireshark question. The switch, which is likely to be managed as you mention VLANs, may have a UI or may support

2024-02-27 13:30:17 +0000 commented question Pcap generation

Both of the products you mention are not part of the Wireshark project so you'll have to look for the appropriate suppor

2024-02-27 10:20:07 +0000 received badge  Rapid Responder (source)
2024-02-27 10:20:07 +0000 answered a question How To Fix Wireshark Time-It is the wrong time?

Wireshark has a preference setting that adjusts the displayed time, see the user guide: https://www.wireshark.org/docs/w

2024-02-23 14:36:27 +0000 edited question Is there a way to analyse socks5 protocol and decode it?

Is there a way to analise socks5 protocol and decode it? Hi! I'm using none-default server port and successfully capturi

2024-02-23 14:36:24 +0000 edited question Is there a way to analyse socks5 protocol and decode it?

Is there a way to analise socks5 protocol and decode it? Hi! I'm using none-default server port and successfully capturi

2024-02-22 09:00:14 +0000 commented answer Read-Filter Option

As per the man page, a "read filter" filters packets using display filter syntax, any that are excluded by the filter ar

2024-02-21 11:55:59 +0000 commented answer Wireshark 4.2 crashes on save config

The bleeding edge installers that have all the latest commits are available at https://www.wireshark.org/download/automa

2024-02-20 14:51:55 +0000 commented answer Check LAN device IP connections

Mikrotik seem to offer some form of packet capture: https://wiki.mikrotik.com/wiki/Manual:Tools/Packet_Sniffer

2024-02-19 09:35:43 +0000 answered a question HOW DO I ORIGINALLY DEPLOY AND USE WIRESHARK AFTER INSTALLHOW DO

Try Chris Greer's beginners guide here: https://www.youtube.com/playlist?list=PLW8bTPfXNGdC5Co0VnBK1yVzAwSSphzpJ

2024-02-19 09:35:43 +0000 received badge  Rapid Responder (source)
2024-02-09 15:53:25 +0000 commented question Web server works but not proprietary software with IP address.

From a remarkably similar physical connection here is filter to another device that is functioning ok(port 44818 all goo

2024-02-09 14:58:33 +0000 received badge  Rapid Responder (source)
2024-02-09 14:58:33 +0000 answered a question Web server works but not proprietary software with IP address.

The client fails to connect as there is no response to the SYN packet.

2024-02-09 14:57:42 +0000 edited question Web server works but not proprietary software with IP address.

Web server works but not proprietary software with IP address. Below is host filter by problem IP. Is there anything pra

2024-02-08 16:30:04 +0000 commented answer Help don't access to public adresse IP

And is there a server running on the good IP and not on the failing IP? Can you check on the server if the required por

2024-02-08 16:28:37 +0000 commented answer Help don't access to public adresse IP

Likely the traffic is being blocked or dropped. Wireshark is unable to tell you why.

2024-02-08 14:55:28 +0000 answered a question Help don't access to public adresse IP

Probably no server listening (or traffic is blocked) on the target port.

2024-02-08 14:55:28 +0000 received badge  Rapid Responder (source)
2024-01-29 13:09:46 +0000 edited answer VM Win 11 Wireshark is not working

I found the answer/statement in the post https://forum.proxmox.com/threads/promiscuous-mode-for-vm.84239/ My Summary: