Re: [tcpdump-workers] tcpdump and wireshark

2008-09-15 Thread Arien Vijn
On 15 sep 2008, at 23:05, Dmitry wrote: Hello. I'm interesting in info extraction from pcap dumps. Recently I did some test dump of downloaded picture with tcpdump and wrote it to file 'dump.pcap'. Test zero: I have started capture on 192.168.0.1 host and did http request of image to 192

Re: [tcpdump-workers] tcpdump and wireshark

2008-09-15 Thread Guy Harris
On Sep 15, 2008, at 2:05 PM, Dmitry wrote: Test one: I've opened dump with wireshark. Found stream, filtered it out and saved raw data to file 'dump.hex' What do you mean by "raw data"? Do you mean raw *binary* data, or raw data as a hex dump? And did you save the raw contents of the pac

[tcpdump-workers] tcpdump and wireshark

2008-09-15 Thread Dmitry
Hello. I'm interesting in info extraction from pcap dumps. Recently I did some test dump of downloaded picture with tcpdump and wrote it to file 'dump.pcap'. Test zero: I have started capture on 192.168.0.1 host and did http request of image to 192.168.0.2 Nothing else dropped to dump except arp r