Nmap Development mailing list archives

Re: npcap doesn't work with wireshark..


From: 食肉大灰兔V5 <hsluoyz () gmail com>
Date: Thu, 14 Apr 2016 23:24:34 +0800

Hi Maayan,

On Thu, Apr 14, 2016 at 10:11 PM, Maayan, Elhanan <Elhanan.Maayan () sbdinc com
wrote:

I'm using 14 version, on win 7 64x I'm using ping for the ip loopback.

I don't know what does you refer to as "ip loopback". Why not just say
127.0.0.1 (for IPv4) and ::1 (for IPv6)? These are publicly known and the
only loopback IPs.
So your ping command will be definitely
"ping 127.0.0.1" or "ping ::1"

I hope you doesn't think 169.x.x.x is a loopback IP.


There no packets coming on that interface on wireshark

The original intent was to let wireshark display packets coming from one software to another on the same machine.
I've almost had it i think on version 13....but the wireshark only displayed packets coming from one end but the 
other did not get them.
I think this was due that originally both software ends were configured to the machine's ip, and from what i 
understand they need to be configured for 169.x.x. ip of ms loopback

There is NO relations between what Npcap Loopback Adapter actually shows
you and the fake IP (169.x.x.x) of Npcap Loopback Adapter recognized by
Windows (like ipconfig command).
So you can't believe a single bit shown by Windows's ipconfig for Npcap
Loopback Adapter.

But version 14 doesn't display anything

I have tested Npcap 0.06 R14, the loopback capture works well.
I believe that you have installed some conflicting software, like VPN,
anti-virus, firewall.
You can uninstall them and try Npcap again.


Cheers,
Yang




 Hi Maayan,

I think you are using npcap-nmap-0.06-r14.exe? What's your OS? Is it a x86
or x64?

And what's your ping command? (I guess you should be aware of using "ping
127.0.0.1" or "ping ::1")

If you didn't see the ICMP and ICMPv6 packets, then does Npcap capture any
other packets on "Npcap Loopback Adapter"? You can attach the capture file
(.pcapng) in the reply.


Cheers,
Yang



On Sun, Apr 10, 2016 at 3:44 AM, Maayan, Elhanan <
Elhanan.Maayan () sbdinc com> wrote:

Hi..



I tried downloading the latest version (n14) and use wireshark 2.0.2, but
even ping doesn’t' seem to register anything in wireshark (I do see the
loopback adapter, and told wireshark to capture packets only from it)

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/



_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

Current thread: