Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 4243] New: WS altering pkt data on Windows Server 2003

Date: Mon, 16 Nov 2009 14:30:26 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4243

           Summary: WS altering pkt data on Windows Server 2003
           Product: Wireshark
           Version: 1.2.3
          Platform: Other
        OS/Version: Windows Server 2003
            Status: ASSIGNED
          Severity: Critical
          Priority: High
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: sudhakar.mogilappagari@xxxxxxxxx
                CC: sudhakar.mogilappagari@xxxxxxxxx


Build Information:
Version 1.3.1 (SVN Rev 30724 from /trunk)

Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.16.6, with GLib 2.20.5, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, without libpcre, without SMI,
without c-ares, without ADNS, with Lua 5.1, without Python, without GnuTLS,
without Gcrypt, without Kerberos, without GeoIP, with PortAudio V19-devel
(built
Oct 26 2009), without AirPcap, with new_packet_list.
NOTE: this build doesn't support the "matches" operator for Wireshark filter
syntax.

Running on Windows Server 2003 x64 Edition Service Pack 2, build 3790, with
WinPcap version 4.1.1 (packet.dll version 4.1.0.1753), based on libpcap version
1.0 branch 1_0_rel0b (20091008).

Built using Microsoft Visual C++ 9.0 build 30729

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
NOTE: Below applies to both the latest stable version and development release

On Windows Advanced Server 2003 SP1/2 (2k3 from now on ), WS is altering the
data that it handing over to the protocol drivers.
I noticed the pkt data on wire and also once it is in the NDIS miniport. But
the data displayed and handed over to protocol drivers is wrong making the
fabric connection not last for long.
I am using WS to capture FCoE traffic. This basically is making WS usability
futile under 2k3.
Winows Advanced Server 2008 doesn't seem to have thsi issue (2k8 is NDIS 6x
etc)


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.