tcpdump mailing list archives
Re: local timestamp recovery of .cap files
From: Guy Harris <guy () alum mit edu>
Date: Thu, 14 May 2009 23:22:04 -0700
On May 14, 2009, at 8:23 PM, Andrej van der Zee wrote:
Hi,2) does, but "helpfully" converts the time to local time (in which case, whoever decided to be "helpful" needs to be hit with said sock).I found that tcpdump with -tttt converts to local time, but tcpdump -tt report GMT.
By "'helpfully' converts the time to local time" I was referring to converting a UNIX seconds-since-the-Epoch/microseconds value to seconds-since-the-Epoch-but-adjusted-to-be-local-time/microseconds value and writing that to the capture file. Converting a UNIX seconds- since-the-Epoch/microseconds value to local time and printing or displaying it, as tcpdump and Wireshark do, is OK; converting a UNIX seconds-since-the-Epoch/microseconds value to seconds-since-the-Epoch- but-adjusted-to-be-local-time/microseconds value and writing that to the capture file is a Very Very Very Very Very Bad Idea, because programs that read pcap files assume the time stamps have seconds- since-the-Epoch/microseconds time stamps, not seconds-since-the-Epoch- but-adjusted-to-be-local-time/microseconds values.
- This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- local timestamp recovery of .cap files Andrej van der Zee (May 14)
- Re: local timestamp recovery of .cap files Guy Harris (May 14)
- Re: local timestamp recovery of .cap files Andrej van der Zee (May 14)
- Re: local timestamp recovery of .cap files Guy Harris (May 14)
- Re: local timestamp recovery of .cap files Jefferson Ogata (May 14)
- Re: local timestamp recovery of .cap files Guy Harris (May 14)
- Re: local timestamp recovery of .cap files Andrej van der Zee (May 14)
- Re: local timestamp recovery of .cap files Guy Harris (May 14)
- Re: local timestamp recovery of .cap files Jefferson Ogata (May 15)
- Re: local timestamp recovery of .cap files Guy Harris (May 15)
- Re: local timestamp recovery of .cap files rh (May 15)
- Re: local timestamp recovery of .cap files Jefferson Ogata (May 15)
- Re: local timestamp recovery of .cap files Andrej van der Zee (May 14)
- Re: local timestamp recovery of .cap files Guy Harris (May 14)