ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] date of using Pcap NG (Michael T?xen)

From: "Faten SOLTANI" <faten.soltani@xxxxxxxxxxxxxxxxxx>
Date: Thu, 7 May 2009 09:42:13 +0200 (CEST)
 Hi

> My question was about  PcapNG, the file which can supprt a mixture of
protocols.
because I have a file which contains a frames from different protocols for
example (ISUP/MTP3 and SIP/IP), and I want to read it by Wireshark, but
before I have to convert it into a format readable by wireshark.
It is impossible with the pcap format because it can support just one data
protocol by file.
so can I convert my file into PcapNG format? if it's possible, How?

> Message: 3
> Date: Wed, 6 May 2009 05:10:39 -0400
> From: Michael T?xen <Michael.Tuexen@xxxxxxxxxxxxxxxxx>
> Subject: Re: [Wireshark-users] date of using Pcap NG
> To: Community support list for Wireshark
> 	<wireshark-users@xxxxxxxxxxxxx>
> Message-ID: <6B19E64E-D1DF-402D-87FB-A5768C3F521C@xxxxxxxxxxxxxxxxx>
> Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
>
> Hi Faten,
>
> I'm not sure what you are especially asking for. But PCAPNG
> support has been added to dumpcap recently. You can try
> it by using the latest development version from the SVN server.
>
> Just add -n as a command line option to dumpcap and the
> file is saved in PCAPNG format. It can be read by Wireshark.
>
> However, this feature is not yet available via the Wireshark
> GUI and the additional information in the PCAPNG file,
> statistics and interface information is not yet displayed
> in the GUI of Wireshark.
>
> Best regards
> Michael
>
> On May 6, 2009, at 4:39 AM, Faten SOLTANI wrote:
>
>> Hello everyone
>> I want to know when the format Pcap-NG (the new format of pcap) can be
>> ready  to use.
>> Cordially
>> Faten
>>
>> ___________________________________________________________________________
>> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx
>> >
>> Archives:    http://www.wireshark.org/lists/wireshark-users
>> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>>
>
>
>
> ------------------------------
>
> Message: 4
> Date: Wed, 6 May 2009 16:55:10 +0530 (IST)
> From: SuNeEl <seacore14@xxxxxxxxx>
> Subject: [Wireshark-users] text2pcap
> To: wireshark-users@xxxxxxxxxxxxx
> Message-ID: <944238.47837.qm@xxxxxxxxxxxxxxxxxxxxxxxxxxx>
> Content-Type: text/plain; charset="utf-8"
>
> Hi all,
>
> why i am not able to convert my hexa dump file of rs232 data to pcap file
> using text2pcap utility ?
>
>
> --
>
> Happiness is like a Butterfly...
>
>
>
>       Now surf faster and smarter ! Check out the new Firefox 3 - Yahoo!
> Edition http://downloads.yahoo.com/in/firefox/?fr=om_email_firefox
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL:
> http://www.wireshark.org/lists/wireshark-users/attachments/20090506/e2dc3373/attachment.htm
>
> ------------------------------
>
> Message: 5
> Date: Wed, 6 May 2009 13:47:17 +0200
> From: "Anders Broman" <anders.broman@xxxxxxxxxxxx>
> Subject: Re: [Wireshark-users] [Suspected Spam]   text2pcap
> To: "Community support list for Wireshark"
> 	<wireshark-users@xxxxxxxxxxxxx>
> Message-ID:
> 	<E48F3A0F80C4B642BF6A5FF3257DFBB906A18D7E@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>
>
> Content-Type: text/plain; charset="us-ascii"
>
> Hi,
> Because you ar not doing it right :-)) possibly?
> Jokes aside text2pcap expects the data to be in the same format as the
> hex pane of Wireshark i think, something like:
> 0000 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00 00 .....
> 0010 00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00 00 .....
> :
> Regards
> Anders
>
> ________________________________
>
> From: wireshark-users-bounces@xxxxxxxxxxxxx
> [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of SuNeEl
> Sent: den 6 maj 2009 13:25
> To: wireshark-users@xxxxxxxxxxxxx
> Subject: [Suspected Spam] [Wireshark-users] text2pcap
>
>
> Hi all,
>
> why i am not able to convert my hexa dump file of rs232 data to pcap
> file using text2pcap utility ?
>
>
> --
>  <http://www.mylivesignature.com>
>
>
> Happiness is like a Butterfly...
>
>  <http://topmasala.com/images/geek2.gif>
>
>
> ________________________________
>
> Own a website.Get an unlimited package.Pay next to nothing.* Click
> here!.
> <http://in.rd.yahoo.com/tagline_ysb_website/*http://in.business.yahoo..c
> om/>
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL:
> http://www.wireshark.org/lists/wireshark-users/attachments/20090506/84260057/attachment.htm
>
> ------------------------------
>
> _______________________________________________
> Wireshark-users mailing list
> Wireshark-users@xxxxxxxxxxxxx
> https://wireshark.org/mailman/listinfo/wireshark-users
>
>
> End of Wireshark-users Digest, Vol 36, Issue 10
> ***********************************************
>