Wireshark mailing list archives

Re: [Wireshark-commits] rev 37826: /trunk/epan/dissectors/ /trunk/epan/dissectors/: packet-rpcap.c


From: Stig Bjørlykke <stig () bjorlykke org>
Date: Wed, 29 Jun 2011 12:24:25 +0200

On Wed, Jun 29, 2011 at 11:34 AM, Jakub Zawadzki
<darkjames-ws () darkjames pl> wrote:
Btw. is there any specification of rpcap?
Or we have only our code and patch for libpcap (from winpcap project)?

WinPcap sources includes this code.  The rpcap dissector was written
using this sources, namely pcap-remote.h.

I've found sf project of rpcap-libpcap from 2002 http://rpcap.sourceforge.net/

I did not know about this rpcap implementation, and surely don't know
which protocol they use :)


My long term project is about adding support for several ways to
capture traffic.  We have dumpcap today, and we may add support for
adding other (custom) programs to capture from other sources using the
same arguments as dumpcap.  In my case we are tracing internal
(proprietary) IPC traffic using a custom capture utility and
presenting the data using Lua scripts.  This combined with a remote
capture functionality can be used in a lab environment to capture from
devices with just a network interface and no console.  I don't know if
rpcap is the ultimate solution, but it works for network traces.


-- 
Stig Bjørlykke
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: