ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] tcpdump capture for wireshark problems

From: Nikolay Shopik <shopik@xxxxxxxxxx>
Date: Thu, 22 Nov 2007 16:00:53 +0300
On 22.11.2007 14:55, Sake Blok wrote:
On Thu, Nov 22, 2007 at 02:24:56PM +0300, Nikolay Shopik wrote:
I'm trying to capture packtes with tcpdump and later view captured file with wireshark but it always tell me what file captured in "middle of something.."
What is the exact message Wireshark displays?
The capture file appears to be damaged or corrupt.
(pcap: Files has 2852126720-byte packet, bigger than maximum 65535)

Did you transfer the file with FTP? Any chance it has been transferred
in ASCII mode instead of BINARY mode? That would result in this error
message, as every 0x0a will be replaced by 0x0d0a when the file is
sent from a unix box to a windows box.

Cheers,


Sake
Yeah I was trying to transfer it via ftp ASCII mode, thanks changing to binary solve problem.