ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-dev: Re: [ethereal-dev] Probable serious bug in ethereal 0.7.8 and 0.7.9 under Linux

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Mike Hall <mlh@xxxxxx>
Date: Thu, 23 Dec 1999 10:15:16 -0600 (EST)
On Thu, 23 Dec 1999, Gilbert Ramirez wrote:

> On Thu, Dec 23, 1999 at 12:59:21PM +0100, Aleksander Adamowski wrote:
> > I think i've stumbled upon a serious bug in ethereal versions 0.7.8 and 0.7.9
> > (0.7.7 works perfectly all right).
> > 
> > Ethereal freezes when capturing packets, and I'm almost sure that it's not the
> > problem you described (the one that occurs under Linux when there's low LAN
> > traffic) - first of all, Ethereal 0.7.7 works perfect, and then our local
> > network is quite loaded with traffic all the time, so it shouldn't be the
> > problem with libpcap for Linux.
> > 

I was having a similar problem with RedHat 6.1. They did something to the
tcpdump and libpcap to allow sniffing on more than one interface at a
time. This changes the file format for pcap and ethereal does the frezze
thing as mentioned. While we should not be frezzing when we encounter this
"version" of pcap, this is an easy fix. Simply get the good clean sources
for libpcap and recompile. And while you at it, make sure you compile in
the linux patch. 

I am assuming since the Mandrake folks follow RedHat, that this is the
Mandrake version of the same problems I was having.

It might be a good idea for us to put up some mandrake/redhat rpm's on the
web site for libpcap and tcpdump. 

Also, I found that the same frezzing occurs when you read a file in that
was saved with the Redhat 6.1 tcpdump using -w. 

What upsets me is that Redhat didn't uprev the version number. They give
you no clue that they changed something like this.

--Mike

+===================================================================+
| Mike Hall               Real programmers dream in Java.           |
| mlh@xxxxxx          Linux rules! Everything else just works.      |
+===================================================================+
|             finger mlh@xxxxxx for public PGP key                  |
+===================================================================+