Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] Strangest thing ever !!! Captures only TCP 3-way handshake negotiation and not any data ?!?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Free Prefix" <free.prefix@xxxxxxxxx>
Date: Thu, 3 May 2007 14:54:27 +0200

Hello All,

Recently I have encountered a very strange phenomenon happens on one
of our new servers.

Server details:
IBM XSeries_3550, Intel Xeon CPU 5130 @ 2 ghz
Network Card: Broadcom BCM5708C NetXtreme II GigE (NDIS VBD Client)
WinPCap 4
Wireshark: 0.99.5

When sniffing network traffic with Wireshark, I can see only the TCP
3-way handshake captured but not the traffic itself afterwards. This
happens using any winsock application including Internet explorer and
such , see attached: Browsing_through_iexplore.cap
The most bizarre thing is that if I am doing "telnet" to the same web
server and passing data through the connection I can indeed see the
traffic, see: Browsing_through_telnet.cap

I thought at first it could be a running Antivirus application or such
that at some level captures the network traffic to analyze viruses
before it reaches winpcap but I doubt it because no such application
exist on the server.

I also tried to play with the advanced features of the card such as:
Jumbo frames, Jumbo MTU size etc,Large Send Offload etc  .... but got
the same results.

I believe it is WinPCap fault, but still any thoughts around this ?

Attachment: Browsing_through_iexplore.cap
Description: Binary data

Attachment: Browsing_through_telnet.cap
Description: Binary data

  • Follow-Ups:
    • Re: [Wireshark-dev] Strangest thing ever !!! Captures only TCP 3-way handshake negotiation and not any data ?!?
      • From: Jeff Morriss
  • Prev by Date: Re: [Wireshark-dev] [Patch] additional lua dissector preference types
  • Next by Date: [Wireshark-dev] Calling other dissectors and returning
  • Previous by thread: Re: [Wireshark-dev] trouble w/ tshark static build on linux
  • Next by thread: Re: [Wireshark-dev] Strangest thing ever !!! Captures only TCP 3-way handshake negotiation and not any data ?!?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation