Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] How to capture the NetBIOS data over 802.2 network

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Mon, 24 May 2004 00:31:58 -0700
On Mon, May 24, 2004 at 11:35:57AM +0800, Bassam A. Al-Khaffaf wrote:
> But the problem here is that even if I increase the snapshot size, tcpdump
> still giving me the header only of the NetBIOS.
> In other words, tcpdump showing me exactly this:
> (15:12:21.446893 NetBeui Packet),
> while I want to read the data inside the NetBeui Packet as Ethereal doing
> it.
> So anyone can give me an idea of how can read the data inside the NetBEUI
> packet?

Run tcpdump with "-vv".  (Continue to use the "-s" flag; "-vv" just
causes tcpdump to print more verbose details of the packet.)

(These are tcpdump questions - there's a "tcpdump-workers@xxxxxxxxxxx"
list on which you can ask tcpdump questions.)