tcpdump mailing list archives
Re: Writing pcap files with fake headers?
From: Guy Harris <guy () alum mit edu>
Date: Tue, 6 Apr 2010 23:18:48 -0700
On Apr 6, 2010, at 7:54 PM, ronnie sahlberg wrote:
Pcap does not have a raw-udp encapsulation, so yours is a reasonable approach.
It does, however, have a raw-IP encapsulation; the link-layer type value in the file header would be 101, and the raw packet data begins with the IP header. A link-layer type value of 1, with a fake Ethernet header (with an Ethertype of 0x0800) followed by a fake IP header, would also work.- This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- Writing pcap files with fake headers? Roy Smith (Apr 06)
- Re: Writing pcap files with fake headers? ronnie sahlberg (Apr 06)
- Re: Writing pcap files with fake headers? Guy Harris (Apr 06)
- Re: Writing pcap files with fake headers? Aaron Turner (Apr 06)
- Re: Writing pcap files with fake headers? Eloy Paris (Apr 06)
- Re: Writing pcap files with fake headers? Michael Richardson (Apr 07)
- Re: Writing pcap files with fake headers? ronnie sahlberg (Apr 06)