Wireshark mailing list archives

Re: Problem writing a file dissector for vwr capture files


From: Hadriel Kaplan <the.real.hadriel () gmail com>
Date: Sun, 30 Aug 2015 07:53:09 -0400

Did you add the magic info into the magic_files array in
wiretap/mime_file.c?  It looks like it's necessary.
-hadriel

On Sun, Aug 30, 2015 at 4:22 AM, Joerg Mayer <jmayer () loplof de> wrote:
Hello,

I'm trying to write a file dissector for the IxVeriWave (.vwr) capture files
(without loosing the ability to open said capture files normally of course)
and am failing:
Running  "tshark -X 'read_format:MIME Files Format' -V -r testfile.vwr" (or
the equivalent steps in wireshark) results in
tshark: The file "testfile.vwr" isn't a capture file in a format TShark understands.
Trying to just take over the complete capture file was also unsuccessful.
I've attached the current source of the dissector. Simple question: What am
I missing ;-)
In case you want to test, use the capture attached to bug 11464.

Thanks
   Jörg


--
Joerg Mayer                                           <jmayer () loplof de>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: