tcpdump mailing list archives
Re: Radio tap headers (DLT 127)
From: Guy Harris <guy () alum mit edu>
Date: Wed, 13 May 2009 15:23:01 -0700
On May 13, 2009, at 3:04 PM, Eddie Harari wrote:
Byte 1 is version byte 2 is pad and byte 3-4 is length of radiotap in bytes right ?
Right.
does this info sit in offset 0 of the data i get when i am sniffing ?
At offset 0 of the data you get from libpcap is the version byte. At offset 1 of the data you get is the pad byte.At offsets 2 and 3 of the data you get is the length of the header. The byte at offset 2 has the low-order 8 bits of the length; the byte at offset 3 has the high-order 8 bits of the length.
If that's not what you're getting, then there's a bug in the operating system or the driver.
What version of what operating system are you using (and, if it's a Linux, what's the version number of the kernel), what wireless adapter are you using, and what driver are you using?
- This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- Radio tap headers (DLT 127) Eddie Harari (May 13)
- Re: Radio tap headers (DLT 127) David Young (May 13)
- Re: Radio tap headers (DLT 127) Eddie Harari (May 13)
- Re: Radio tap headers (DLT 127) Guy Harris (May 13)
- Re: Radio tap headers (DLT 127) Eddie Harari (May 13)
- Re: Radio tap headers (DLT 127) Eddie Harari (May 13)
- Re: Radio tap headers (DLT 127) David Young (May 13)