Wireshark-users: [Wireshark-users] Editcap and timestamps
From: Wu Weidong <hjazz6@xxxxxxxxx>
Date: Thu, 4 Aug 2011 23:54:05 -0700 (PDT)
| Hi, Does editcap depend on packet timestamp in anyway? I was able to extract specific packets using editcap on pcap files that were recorded from live traffic, but was unable to extract any packets on processed pcap files that have packet timestamps as 0. Thank you. Regards, Rayne |
- Follow-Ups:
- Re: [Wireshark-users] Editcap and timestamps
- From: Jeff Morriss
- Re: [Wireshark-users] Editcap and timestamps
- Prev by Date: Re: [Wireshark-users] Knowing What Exploit from .pcap File
- Next by Date: Re: [Wireshark-users] Knowing What Exploit from .pcap File
- Previous by thread: Re: [Wireshark-users] Scanning subnetwork considered bad or not?
- Next by thread: Re: [Wireshark-users] Editcap and timestamps
- Index(es):





