Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] USB

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Jim Paris <jim@xxxxxxxx>
Date: Tue, 3 Apr 2007 00:37:59 -0700

I would like to start playing with the USB dissector in Wireshark.  

My USB capture hardware will give me complete USB packets, i.e. all of
the data on the wire between the SOP and EOP markers.  However, I'm
not clear on how this fits into the DLT_USB or DLT_USB_LINUX capture
types.  It seems that even the "raw" DLT_USB is a higher-level view offb
USB, above the actual USB packet format on the wire, in that it has
complete URBs instead of actual packets like IN, DATA0, SOF, ACK, etc.

Given that I have real raw USB packets, any suggestions on what to do
to get those into Wireshark?  Could the existing USB dissector still
be useful or would this entail creating a whole new DLT_* type and
dissector?

-jim

  • Follow-Ups:
    • Re: [Wireshark-dev] USB
      • From: Guy Harris
    • Re: [Wireshark-dev] USB
      • From: Charles Lepple
  • Prev by Date: Re: [Wireshark-dev] dissector for OpenVPN
  • Next by Date: Re: [Wireshark-dev] USB
  • Previous by thread: Re: [Wireshark-dev] [PATCH] packet-skinny: well formed DialedNumberMessage displayed as malformed.
  • Next by thread: Re: [Wireshark-dev] USB
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation