Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Help.. pcap to ivs

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 13 Mar 2008 20:16:56 -0700

On Mar 13, 2008, at 3:21 PM, Andrea Faver wrote:

i'm trying to convert a pcap file (made with WIRESHARK) to a ivs file
with aircrack ivstools.exe but it doesn't recognize the file. how can i
do it?
When i save my captured packed in WIRESHARK, in wich format should i do
it? (i have several option, wireshark, modified tcdump, redhat6.1,
suse6.3...)


Wireshark's default format is "Wireshark/tcpdump/... - libpcap" (that's why it says "Wireshark" in the name of that format :-)). That's the standard libpcap format that is also used by, for example, tcpdump/WinDump.

The other formats are non-standard, and ivs might, or might not, be able to understand them (it probably doesn't understand some of them).