Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: Re: [Ethereal-dev] Tapping

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

Date Prev · Date Next · Thread Prev · Thread Next
From: ronnie sahlberg <ronniesahlberg@xxxxxxxxx>
Date: Fri, 1 Oct 2004 12:49:59 +1000
On Thu, 30 Sep 2004 19:35:50 -0700 (PDT), Guy Harris  wrote:
> ronnie sahlberg said:
> >> Is it possible to write a tapping for an existing protocol without
> >> making any changes on the source code (Assuming that the protocol
> doesn't have
> >> a tap device installed on it.)?
> > No
> 
> Couldn't a tap just get the protocol tree and process that?  (That might
> not supply enough information, and the protocol tree is somewhat of a pain
> to process, but if he really wants to build a tap for an existing protocol
> without modifying the dissector, that's about all he can do....)

yes   it could do that but as you point out, it would be a very painful way to
process the packets.
it would be much less painful to just tappify the protocol he is interested in.