tcpdump mailing list archives

Re: [RESEND][PATCH] enable sniff on USB ports on linux (BSD license)


From: "ronnie sahlberg" <ronniesahlberg () gmail com>
Date: Tue, 3 Oct 2006 11:21:27 +1000

No   it is for "raw" usb frames  with some additional infomation added by
the capturing layer.

Some of these frames, those captured when talking to a memorystick, will
likely contain SCSI CDBs and DATA frames in some layer above the actual usb
layer
but other frames might contain different commandsets such as keyboard/mouse
i/o.




On 10/3/06, Michael Richardson <mcr () sandelman ottawa on ca> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


>>>>> "Guy" == Guy Harris <guy () alum mit edu> writes:
    >> The USB pseudo headers are still in a separate file, must I move
    >> them into pcap.h ?!?

    Guy> Not necessarily.

    Guy> If we have a separate header, however, I'd prefer to create a
    Guy> "pcap" subdirectory of the top-level include directory
    Guy> ("/usr/include", "/usr/ local/include", etc.), and put pcap.h
    Guy> there, with "{top level include directory}/pcap.h" being just

  I concur.

    >> I have to fix also the dlt issue. Can you please assign a new DLT
    >> value for me ?

    Guy> I've added DLT_USB, with a value of 186.

  Stupid me... is this for IP over USB, or is it for something weirder,
like treating SCSI over USB as iSCSI...?

- --
]            Bear: "Me, I'm just the shape of a
bear."          |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net
architect[
] mcr () xelerance com      http://www.sandelman.ottawa.on.ca/mcr/ |device
driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security
guy"); [



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Finger me for keys

iQEVAwUBRSGyS4CLcPvd0N1lAQLvuAf/a/AYlN9trspSBnsE4BU8waIuOSg5HIw8
hqgD3I7JATYJsW2BeV86Zl4cbptQdP7jDHLWiTFfb1FhFisk2Wvb4zR4Gg9CLFYD
G1h+QCtoPI3cWO1lqMcOBfHs20IW5Uzu8xVeRsIe4oGB7Bdwz5/Gmo89Bn8r8Bld
J8Rkf4xcHHusurjKN3UbrkTM65PLk40NMaN161TTexkmyFFjZeogXiFcbqIZKYPc
jG30cEO3SXhhJpFa2dQyj2h9T3fTDc3hXZsIfBGv6GrRL4WNDAbd4McWP+qn7g/8
sQQ/V6tF+Za751IauLNDQ53YV2PGEFFppQS9Rn3Tt8hrkX8x7lPRLA==
=fnoQ
-----END PGP SIGNATURE-----
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.

-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: