Nmap Development mailing list archives

Re: npcap doesn't work with wireshark..


From: "Maayan, Elhanan" <Elhanan.Maayan () sbdinc com>
Date: Thu, 14 Apr 2016 14:11:08 +0000

I'm using 14 version, on win 7 64x I'm using ping for the ip loopback.

There no packets coming on that interface on wireshark

The original intent was to let wireshark display packets coming from one software to another on the same machine.
I've almost had it i think on version 13....but the wireshark only displayed packets coming from one end but the other 
did not get them.
I think this was due that originally both software ends were configured to the machine's ip, and from what i understand 
they need to be configured for 169.x.x. ip of ms loopback
But version 14 doesn't display anything





Hi Maayan,

I think you are using npcap-nmap-0.06-r14.exe? What's your OS? Is it a x86 or x64?

And what's your ping command? (I guess you should be aware of using "ping 127.0.0.1" or "ping ::1")

If you didn't see the ICMP and ICMPv6 packets, then does Npcap capture any other packets on "Npcap Loopback Adapter"? 
You can attach the capture file (.pcapng) in the reply.


Cheers,
Yang



On Sun, Apr 10, 2016 at 3:44 AM, Maayan, Elhanan <Elhanan.Maayan () sbdinc com<mailto:Elhanan.Maayan () sbdinc com>> 
wrote:
Hi..

I tried downloading the latest version (n14) and use wireshark 2.0.2, but even ping doesn’t' seem to register anything 
in wireshark (I do see the loopback adapter, and told wireshark to capture packets only from it)

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: