ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-users: Re: [Ethereal-users] Supported cap files

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Wed, 31 Oct 2001 00:07:14 -0800
On Wed, Oct 31, 2001 at 08:26:43AM +0100, Maet.W wrote:
> Does Ethereal also read *.cap files from NexusTrace ?

No.

> Info on NexusTrace can be found at following url:
>  HYPERLINK http://www.nexus-ag.com/NexusWeb2001/products/nexusTRACE.htm
> http://www.nexus-ag.com/NexusWeb2001/products/nexusTRACE.htm

Unfortunately, I don't see anything obvious there describing the capture
file format, so we'd have to reverse-engineer the format.

> I also attached a sample cap file

In order to reverse-engineer it, we'd probably need another capture file
(in the hopes of determining whether it has a "magic number" at the
beginning, so that we can recognize the files) - preferably a capture
file from a different type of network (what type of network was that
capture from?) - and detailed printfiles from both of the captures (so
we can see what NexusTrace thinks is in the file, and perhaps find where
time stamps, packet lengths, packet data, etc. are stored).

There's no guarantee that we'd be able to reverse-engineer the file
format, or that it could be done in a short period of time.

If you can find documentation on the capture file format, that would
help a *lot*.