Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Guy Harris
On Dec 22, 2008, at 1:18 PM, Matthias Wenzel wrote: Guy Harris wrote: So DECT and DECT 6.0 are close enough that they can use LINKTYPE_DECT/DLT_DECT? Yes. DECT has 10 radio channels, DECT 6.0 has 5, they all fit into one 0-63 channel table scheme in ETSI EN 300 175-2, Annex F (mostly unlice

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Guy Harris
On Dec 22, 2008, at 1:58 PM, Matthias Wenzel wrote: I just had a look, and thanks for pointing me there. But that seems very device independant. To me it seems its a generic way to record URBs on a USB bus in pcap, but correct me if I am wrong. I think he meant to look at it as an example

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Matthias Wenzel
ronnie sahlberg wrote: >>> On Dec 22, 2008, at 1:51 AM, Matthias Wenzel wrote: >> Not as of now. We're not capturing from neiter a tun/tap device, nor a >> network interface. For now we have a driver with a char device, some >> ioctls and firmware. >> In future we may implement a virtual network de

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread ronnie sahlberg
On Tue, Dec 23, 2008 at 8:18 AM, Matthias Wenzel wrote: > Guy Harris wrote: >> >> On Dec 22, 2008, at 1:51 AM, Matthias Wenzel wrote: >> >>> we have a set of opensource tools that read and write pcap files from/to >>> DECT devices. The SW will go public still this year. We're working with >>> both

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Matthias Wenzel
Guy Harris wrote: > > On Dec 22, 2008, at 1:51 AM, Matthias Wenzel wrote: > >> we have a set of opensource tools that read and write pcap files from/to >> DECT devices. The SW will go public still this year. We're working with >> both gnuradio USRP and a dedicated HW. > > Could the code to captu

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Maciej Grela
2008/12/22 Guy Harris : > > On Dec 22, 2008, at 1:51 AM, Matthias Wenzel wrote: > >> we have a set of opensource tools that read and write pcap files from/to >> DECT devices. The SW will go public still this year. We're working with >> both gnuradio USRP and a dedicated HW. > > Could the code to ca

Re: [tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Guy Harris
On Dec 22, 2008, at 1:51 AM, Matthias Wenzel wrote: we have a set of opensource tools that read and write pcap files from/to DECT devices. The SW will go public still this year. We're working with both gnuradio USRP and a dedicated HW. Could the code to capture DECT traffic go into libpca

Re: [tcpdump-workers] Protocol headers-only capture?

2008-12-22 Thread Dustin Spicuzza
Dustin Spicuzza wrote: > Dustin Spicuzza wrote: > > And it will rotate the logs around every half hour storing only headers. > Of course the only part I did was add the -s headers option.. > Oh, on a related note, if you use the rotate functionality and you tell it to drop privileges, then it f

Re: [tcpdump-workers] Protocol headers-only capture?

2008-12-22 Thread Dustin Spicuzza
Dustin Spicuzza wrote: > Guy Harris wrote: >> On Dec 17, 2008, at 2:30 PM, Dustin Spicuzza wrote: >> >>> Speaking of which, is there something in tcpdump that can figure out how >>> long the header is... I see that the printers figure out this >>> information, but its not done separately as far as

[tcpdump-workers] Request for DECT LINKTYPE

2008-12-22 Thread Matthias Wenzel
Hi, we have a set of opensource tools that read and write pcap files from/to DECT devices. The SW will go public still this year. We're working with both gnuradio USRP and a dedicated HW. For what you may want to know there are basically 3 types of DECT out there (from what I know): 1) DECT - th