Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] newbie question

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Alexandros Papadopoulos <apapadop@xxxxxxxxxxxxxx>
Date: Mon, 4 Apr 2005 12:28:06 +0300
On Saturday 02 April 2005 18:54, linux lover wrote:
> Hello all,
>           I just joined this list. 

Welcome! I'd suggest you read 
http://www.catb.org/~esr/faqs/smart-questions.html
to make the most out of your mailing list(s) experience.

>           I use Ethereal and 
> found that for each captured packet ethereal displays
> not only its detail info but HEX dump at bottom.
>           I also want to study how it works and how
> can i add new protocol to it. What i first want to
> know is that which function in ethreal source code
> display that hex info? How ethereal captures packets?

libpcap does the capturing. You can find the source code of the library 
at http://www.tcpdump.org/

-A