Re: [tcpdump-workers] proposed new pcap format

2004-03-27 Thread Michael Richardson
often only at the beginning of the file - but let's not build that assumption into any software which reads files. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PRO

Re: [tcpdump-workers] proposed new pcap format

2004-03-27 Thread Michael Richardson
things, first-come/first-served. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just ano

Re: [tcpdump-workers] proposed new pcap format

2004-03-27 Thread Michael Richardson
s as people need them. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/

Re: [tcpdump-workers] proposed new pcap format

2004-03-27 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- >>>>> "Guy" == Guy Harris <[EMAIL PROTECTED]> writes: Guy> On Mar 24, 2004, at 7:08 AM, Michael Richardson wrote: >> okay, but there is more than just in/out. >> >> enum pcap1_probe { &g

Re: [tcpdump-workers] movement of lists

2004-03-28 Thread Michael Richardson
essage. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using,

Re: [tcpdump-workers] timestamps and timezone

2004-03-29 Thread Michael Richardson
, you If one had a program that started a new dump file each "local" day, then it might be good to know why the file ends at 8pm or something each time. That's a pretty big stretch, though. Otherwise, I agree with you. - -- ] ON HUMILITY: to err is human. To moo, bovine.

[tcpdump-workers] tcpdump 3.8.2

2004-03-29 Thread Michael Richardson
[ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -BEGIN PGP SIGNATURE- Version: GnuPG v

[tcpdump-workers] ADMIN

2004-03-29 Thread Michael Richardson
lling to help, let me know. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another

Re: [tcpdump-workers] proposed new pcap format

2004-04-02 Thread Michael Richardson
o Darren> [EMAIL PROTECTED] Darren> [EMAIL PROTECTED] it should now be [EMAIL PROTECTED] [EMAIL PROTECTED] should alias there. [EMAIL PROTECTED] or @lists.sandelman should bounce. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael

[tcpdump-workers] aclocal.m4 and openssl

2004-04-03 Thread Michael Richardson
LITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security

[tcpdump-workers] print-esp, AES

2004-04-04 Thread Michael Richardson
crypt AES256 packets generated by Openswan. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(

Re: [tcpdump-workers] Proposed new pcap format

2004-04-05 Thread Michael Richardson
To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [

Re: [tcpdump-workers] print-esp, AES

2004-04-05 Thread Michael Richardson
he 3.8 branch as well? yes, assuming that we do a 3.8.4. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |de

[tcpdump-workers] Bill Fenner: Did this message ever make it to the tcpdump list?

2004-04-07 Thread Michael Richardson
From: Bill Fenner <[EMAIL PROTECTED]> Subject: Re: [tcpdump-workers] aclocal.m4 and openssl Date: Mon, 5 Apr 2004 11:05:36 -0800 To: [EMAIL PROTECTED] I've been meaning to revisit aclocal.m4 and the autoconf setup for a long time. Much of it was hand-spun to get around bugs or limitations in aut

Re: [tcpdump-workers] Proposed new pcap format

2004-04-12 Thread Michael Richardson
Draft that defines a standard network trace format. a) I think that the INCH WG has done some work in this area. b) It isn't clear that file formats are within the IETF purvue. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson

Re: [tcpdump-workers] bpf/pcap performance

2004-04-12 Thread Michael Richardson
rren> pcap_dispatch() but none of the others really help. Unless Darren> all your classes are static classes (which kind of defeats Darren> the purpose, in my book.) Dareen, can you suggest a better interface? One that is friendly to C++ without requiring that we drag in any C++ c

Re: [tcpdump-workers] proposed new pcap format

2004-04-12 Thread Michael Richardson
ften this occurs for me in writing test cases, but also in trying to understand what has broken in a network. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://

Re: [tcpdump-workers] Proposed new pcap format

2004-04-12 Thread Michael Richardson
and filled in later on) c) do we include this in every packet header? Or as an extra meta-attribute? - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED]

Re: [tcpdump-workers] Proposed new pcap format

2004-04-12 Thread Michael Richardson
e packet data, we need to define things. I can see some people wanting a hash over the layer-3 only, with mutable fields set to zero (a la IPsec AH), such that they can compare captures from different points. Is this your desire? - -- ] ON HUMILITY: to err is human. To moo, bovine.

Re: [tcpdump-workers] Proposed new pcap format

2004-04-16 Thread Michael Richardson
nd add appropriate data later on. Maybe it can do after-the-fact hashing as well. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.

Re: [tcpdump-workers] Proposed new pcap format

2004-04-16 Thread Michael Richardson
ism in 2) needs to be sufficient to handle the hashes Guy> from 1) as well as other hashes people might want to provide, Guy> but that mechanism itself is somewhat decoupled from the Guy> hashing in 1). On this I agree. - -- ] ON HUMILITY: to err is human. To mo

Re: [tcpdump-workers] Proposed new pcap format

2004-04-16 Thread Michael Richardson
quot;optional". Only for standards track :-) - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("

Re: [tcpdump-workers] Proposed new pcap format

2004-04-20 Thread Michael Richardson
ommend that capture mechanisms implement it. Darren> Yes, I like that approach. My objection is to their being a Darren> "default" (aside from not having one) that everyone is Darren> expected to use/support, regardless of others. Since the file could be re-proces

Re: [tcpdump-workers] Proposed new pcap format

2004-04-20 Thread Michael Richardson
mean the same thing. And with GbE encoding, ECC memory and parity protected L3 cache buses, the PCI bus *is* the least reliable interface in a typical PC. I believe that people who do TCP checksum offload have experienced this problem already. - -- ] ON HUMILITY: to err is human. To

Re: [tcpdump-workers] little fix for print-esp.c

2004-04-20 Thread Michael Richardson
LITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [

Re: [tcpdump-workers] proposed new pcap format

2004-04-20 Thread Michael Richardson
Stephen> nanoseconds then the effective stored resolution is limited Stephen> to that anyway. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http:

[tcpdump-workers] ADMIN - checking

2004-05-04 Thread Michael Richardson
okay, my stupid. List should be alive again. I can't tell you how much grief switching from lists.sandelman.ca -> lists.tcpdump.org has caused. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON

[tcpdump-workers] ADMIN - checking

2004-05-04 Thread Michael Richardson
This is a test of the list. My appologies for the problems. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device

[tcpdump-workers] netdissect.h

2004-04-30 Thread Michael Richardson
be "ndo" rather than "gndo". Once we are done all of the files, there will be some dead code in tcpdump.c that we can get rid of, and then we can refactor some of the remaining code a bit more. I hope everyone can see the point of this effort. - -- ] ON HUMILITY: to

[tcpdump-workers] IGRP

2004-04-28 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hannes, ipproto.c has IPPROTO_IGRP, but ipproto.h doens't define it. Is this supposed to be protocol=9 ("IGP"), which you have as IPPROTO_PIGP, or??? - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Mic

Re: [tcpdump-workers] tok2str() patch

2004-04-29 Thread Michael Richardson
shouldn't be an issue, I think. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just anot

Re: [tcpdump-workers] IPv6 dependency

2004-04-29 Thread Michael Richardson
anding that tcpdump already supported v4-only environments. Perhaps if you could tell us a bit more about your platform and provide the ./configure output, we could better understand why it is failing for you. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael

Re: [tcpdump-workers] IPv6 dependency

2004-04-29 Thread Michael Richardson
Okay, it has been years since I was on a v6-crippled system, so I didn't know that we weren't OS independant. Can we extract some in6_addr code from one of the BSDs and include that if we need it? -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ]

Re: [tcpdump-workers] pcap1.0

2004-05-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I hosted a BOF on Saturday morning about libpcap 1.0 at bsdcan.org. Here are the notes that I took. A lot of people were very interested in helping with this. I hope they will soon be on the list. LINKTYPE enumeration. - metadata about linktype in file. M

Re: [tcpdump-workers] pcap1.0

2004-05-16 Thread Michael Richardson
needs more discussion. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another

Re: [tcpdump-workers] pcap_stats

2004-05-19 Thread Michael Richardson
7;t add it to the count of drops, as it's *already* a count since the capture started; just set the count of drops to the value". Do so. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa

Re: [tcpdump-workers] anon cvs problem??

2004-05-30 Thread Michael Richardson
tomorrow. The dailies still exist if you want CVS head. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |d

[tcpdump-workers] web stats

2004-06-03 Thread Michael Richardson
Is there a volunteer that might want to collect the apache logs from all the various tcpdump.org mirrors, combine them and summarize things every month or quarter? A typo in my /etc/newsyslog.conf just filled the /tcpdump partition with the log file (it wasn't getting rolled). - This is the

[tcpdump-workers] anoncvs

2004-06-03 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- the pserver is updated to 1.11.16, and has been re-enabled. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED]

Re: [tcpdump-workers] [PATCH] Drop unneeded capabilities

2004-06-24 Thread Michael Richardson
ke the ability to call connect(2) means that an attacker can't get out again, even if they are non-root. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PRO

Re: [tcpdump-workers] text format stability

2004-06-25 Thread Michael Richardson
"Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using,

[tcpdump-workers] anoncvs

2004-06-28 Thread Michael Richardson
the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, se

[tcpdump-workers] new capture file format

2004-06-30 Thread Michael Richardson
x27;ve been going around inviting various users of libpcap to come and take a look. Other than that, we just need to find someone willing to take notes and issue revised proposals. There is no point in writing code until then. - -- ] "Elmo went to the wrong fundraiser" - T

Re: [tcpdump-workers] text format stability

2004-06-30 Thread Michael Richardson
t;Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking,

[tcpdump-workers] XML dissector output

2004-06-30 Thread Michael Richardson
g" => "value" } format. The question is -- how to retain what we have now? Does each level of dissector register a "print" function as well? (with XML output all using the common XML print function?) Or is some other structure that someone can think of. - -- ]

Re: [tcpdump-workers] text format stability

2004-06-30 Thread Michael Richardson
i.e.: rather than: 0x45 It does use the container mechanism to do sub-structure, but I'm not convinced that I like it this. It is worth looking at. How widespread is PDML? - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael

Re: [tcpdump-workers] tcpdump-current.tar.gz

2004-07-03 Thread Michael Richardson
if you need pserver, I've turned it on again, but limited it by hosts.allow. I'll rejig stuff a bit. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [

[tcpdump-workers] spam to tcpdump-announce

2004-07-07 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Sorry, I noticed that tcpdump-announce was open to spammers. It is closed now. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect

Re: [tcpdump-workers] Building tcpdump 3.8.3 undex Solaris 2.9

2004-07-20 Thread Michael Richardson
;s fixed in the current CVS tree. Guy> Michael, should we put out a libpcap 0.8.4/tcpdump 3.8.4 Guy> release with the fixes that have been added since then? I guess. Are there other things that should be slipped in? - -- ] "Elmo went to the wrong fundraiser" -

Re: [tcpdump-workers] anoncvs down?

2004-07-21 Thread Michael Richardson
lmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking,

Re: [tcpdump-workers] Tcpdump time discrepancy (vs ethereal/tcptrace)

2004-07-22 Thread Michael Richardson
; reading, but before processing, the first packet, so the offset Guy> from UTC is appropriate to the time of the first packet, not to Guy> the time when tcpdump called "time()" in "gmt2local()". I think your analysis is right. - -- ] "Elmo went to

[tcpdump-workers]

2004-07-26 Thread Michael Richardson
TED]> To: "Guy Harris" <[EMAIL PROTECTED]>, "Loris Degioanni" <[EMAIL PROTECTED]> Cc: "Fulvio Risso" <[EMAIL PROTECTED]>, "Michael Richardson" <[EMAIL PROTECTED]> References: <[EMAIL PROTECTED]> <[EMAIL PROTECTED]> Subject

[tcpdump-workers] anoncvs for tcpdump.org.

2004-08-19 Thread Michael Richardson
rough this and determine if this is a real problem, or what. I guess, if you do anon-cvs to lox.sandelman.ca, it may work. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corpora

Re: [tcpdump-workers]

2004-09-07 Thread Michael Richardson
From: [EMAIL PROTECTED] >[1. text/plain] >drugs? ... > >[2. application/x-zip-compressed; regid_object.zip]... > >[3. text/plain] Henceforth, only text/plain will be permitted on the list. -- ] "Elmo went to the wrong fundraiser" - The Simpson

Re: [tcpdump-workers] Trace conversion.

2004-09-17 Thread Michael Richardson
perl script to pull out the data you want. Paul> I suspect this wouldn't be too hard if the tcpdump format was Paul> specified, but if it is, I can't find such a document. get libpcap source, and read pcap.h and pcap.3 - -- ] "Elmo went to the wrong fundrais

Re: [tcpdump-workers] ello! =))

2004-09-23 Thread Michael Richardson
draiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ - This is

Re: [tcpdump-workers] "final" radiotap patch for tcpdump

2004-09-23 Thread Michael Richardson
in line with mainline Bruce> tcpdump/libpcap again. Okay, so can it get integrated into CVS HEAD, and I will arrange to do a 3.9, 0.9. -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON

Re: [tcpdump-workers] importing libpcap 0.8.3, UPDATE

2004-09-23 Thread Michael Richardson
rivate patches from thorpej, itojun, and others. itojun at least, is on this list. Can we get all of these things into HEAD, if they aren't there already? David, you have the power. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] M

Re: [tcpdump-workers] "final" radiotap patch for tcpdump

2004-09-23 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- >>>>> "Guy" == Guy Harris <[EMAIL PROTECTED]> writes: Guy> Michael Richardson wrote: >> Okay, so can it get integrated into CVS HEAD, and I will arrange >> to do a 3.9, 0.9. Guy> HEAD, or HEAD

Re: [tcpdump-workers] x.9 branch

2004-10-11 Thread Michael Richardson
PRE-CVS" and "3.9-PRE-CVS", Guy> respectively? okay. -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.o

Re: [tcpdump-workers] Dropping Packets

2004-10-04 Thread Michael Richardson
Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hackin

Re: [tcpdump-workers] tcpdump with Linux 2.6 and ipsec/ESP

2004-10-05 Thread Michael Richardson
unaware of the other two. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic(&

Re: [tcpdump-workers] tcpdump -E doesn't work for 3des-cbc/hmac-md5

2004-10-05 Thread Michael Richardson
tatement that the authlen isn't set. Perhaps it is really that the algorithm has not been set correct by th reporters. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architec

Re: [tcpdump-workers] tcpdump -E doesn't work for 3des-cbc/hmac-md5

2004-10-05 Thread Michael Richardson
ceed in the same direction. The problem is that the last two bytes of the plaintext are special in ESP. Last byte is the next-protocol (usually 4), and next to last is the number of pad bytes. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michae

Re: [tcpdump-workers] Bad PGP signatures

2004-10-09 Thread Michael Richardson
ed with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 0227 54EB 4C30 9185 FD31 33A3 464D 3CEB 89E9 17F3 - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,

Re: [tcpdump-workers] IPSEC question

2004-10-17 Thread Michael Richardson
e wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, secur

Re: [tcpdump-workers] dealing with collisions, dropped packets

2004-11-01 Thread Michael Richardson
coming in off a hub Matt> be shown as dropped? I'm seeing a traffic feed of roughly Well, you need to ask your operating system about that. tcpdump runs on about a dozen different systems. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls

Re: [tcpdump-workers] dealing with collisions, dropped packets

2004-11-01 Thread Michael Richardson
; will increment over time. Other errors and statistics are Aaron> also available. Those are transmit side collisions. - -- ] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [ ] Michael Richardson,Xelerance Corporation, O

Re: [tcpdump-workers] Adding my own IP layer protocol interface to

2005-01-14 Thread Michael Richardson
icates that there's an IP header after the AH header? Guy> A special value in the "next header" field of the AH header? - maybe he has to edit print-ah.c. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com

Re: [tcpdump-workers] can't do CVS checkouts/updates anymore

2005-02-07 Thread Michael Richardson
don't have a static. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ] panic("Just ano

Re: [tcpdump-workers] displaying package content only

2005-02-09 Thread Michael Richardson
TML-content of sascha> a website for example. sascha> can anyone help me in tweaking? Use snort or dsniff. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.s

Re: [tcpdump-workers] TCPDUMP version 3.8.3

2005-03-22 Thread Michael Richardson
(POSIX?) system, when the process exits, then the operating system reclaims all resources. If you aren't running on such a system, then yes, you probably have a problem. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com N

[tcpdump-workers] FYI: I'm lame

2005-03-22 Thread Michael Richardson
not in my face anymore, so I may not read it in a timely way. I'm not reading tcpdump-workers via gmane.org. I try to catch up once a week, so if it is critical, please email me. Please try to PGP sign, as that gets my highest attention. - -- ] Michael Richardson Xelerance Cor

Re: [tcpdump-workers] HTTP Auth filter

2005-03-30 Thread Michael Richardson
; but so far I have no clue on where to start. google "dsniff" - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/

[tcpdump-workers] preperation for 3.9 branch

2005-04-04 Thread Michael Richardson
) verify builds on various platforms d) gather any updates from distro maintainers e) update freshmeat. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http

[tcpdump-workers] fddipad on NetBSD

2005-04-06 Thread Michael Richardson
diff -r1.68 pcap-int.h 246c246 < #if defined(ultrix) || defined(__osf__) || defined(__NetBSD__) - --- > #if defined(ultrix) || defined(__osf__) || (defined(__NetBSD__) && > __NetBSD_Version__ > 10600) I'll pull this up into the next beta, unless someone has a

Re: [tcpdump-workers] libpcap Patches and Release Cycle?

2005-04-06 Thread Michael Richardson
2) The main website says 0.9.0 went alpha today (the link to GSE> the source is broken btw). What is the normal delay before GSE> formal release? I said we'd branch on April 10, release around the 30th. The branch is early, for self-interested reasons :-) - -- ] Michael

Re: [tcpdump-workers] fddipad on NetBSD

2005-04-06 Thread Michael Richardson
versions - did you try it on 2.0, for example?). - This is the I have yet to upgrade anything to 2.0, which is on my todo list. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://w

Re: [tcpdump-workers] preperation for 3.9 branch

2005-04-06 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- >>>>> "Guy" == Guy Harris <[EMAIL PROTECTED]> writes: Guy> Michael Richardson wrote: >> I would like to plan a 3.9 branch and release for April. I would >> propose branching on April 10, with the relea

Re: [tcpdump-workers] pcap next gerneration / adding communication

2005-04-09 Thread Michael Richardson
annes> capture-file.pcap Yeah, this is probably the best thing. Use the tools to build a good system. The sudo can be made passwordless for certain groups, and can force the command, or in the case of systems with BPF devices, the device can be chgrp'ed. - -- ] Michael Richards

Re: [tcpdump-workers] Welcome to the tcpdump-workers list!

2005-04-12 Thread Michael Richardson
p doesn't have sending packets as a goal, I'd say that libdnet supports sending on an infinite more than libpcap. Use the right tool for the job. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec trainin

[tcpdump-workers] spam on tcpdump-workers list

2005-04-12 Thread Michael Richardson
ages go through. I hope it isn't a trend. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ] pan

Re: [tcpdump-workers] Mailing List Info/Procedural Questions

2005-04-15 Thread Michael Richardson
orkers/ I'd like to avoid Jeff> repeating questions that you all might have just answered last Jeff> month. Hmm. looks like something broke. visit lists.ox.org, and select lists.tcpdump.org, login with your list password, and you can see the archives there. I'll have to

Re: [tcpdump-workers] preperation for 3.9 branch

2005-04-25 Thread Michael Richardson
turday. (May 1). I am behind on email, but I gather that there is some new vulnerability that needs to be addressed. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sand

Re: [tcpdump-workers] (3) tcpdump infinite loop bugs... (2 fixed

2005-04-25 Thread Michael Richardson
; didn't run them to check that it's really the case, Romain> though... did you? btw, do we have exploit packets in CVS yet? (under tests/) I'd like to see them as regression test cases... - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewall

[tcpdump-workers] hold up on 3.9

2005-06-02 Thread Michael Richardson
diapers to change... - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]I'm

[tcpdump-workers] any objection to -P flag -- exit after packet limit

2005-06-04 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I added the -P flag, which takes a positive number, and has tcpdump exit after capturing that many packets. It can be combined with the -C flag, but it doesn't cause it to cycle after that many packets, rather the two work independantly. I found I wanted thi

Re: [tcpdump-workers] Any news/updates for the release libpcap 0.9?

2005-06-21 Thread Michael Richardson
ou could do that, it would permit the release to go out. It is about 2-3 hours of work. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/m

[tcpdump-workers] 3.9.1

2005-07-05 Thread Michael Richardson
g on nearly every platform, including improved 64bit support MSDOS Support Add support for sending packets OpenBSD pf format support IrDA capture (Linux only) - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ]

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-05 Thread Michael Richardson
g; ++Xflag; ++Aflag; break; - Guy added that line 19-Dec-2002. Guy, can you defend this change? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mc

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-05 Thread Michael Richardson
added that line 19-Dec-2002. Guy> The "++xflag;" line? Yeah, I didn't look too closely, just did a cvs annotate... Looks like the problem is elsewhere, in the printer. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xeler

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-05 Thread Michael Richardson
submit a patch done with 3.8.x that shows what you want, and put it in the tests subdir? I.e. same input, each possible -x,-X,-A combination, and your expected output. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing I

Re: [tcpdump-workers] 3.9.1

2005-07-06 Thread Michael Richardson
h Ken's work. Oops. Fixed in CVS. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driver[ ]

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-06 Thread Michael Richardson
hes/tcpdump-3.9.1-test-print-flags.patch I committed those files to HEAD. Now, we need to commit the fix :-) - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sa

Re: [tcpdump-workers] 3.9.1 -A flag broken

2005-07-06 Thread Michael Richardson
The list filters out non-text/plain mime types. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |dev

Re: [tcpdump-workers] detecting libpcap 0.9

2005-07-06 Thread Michael Richardson
>> the aforementioned change. Romain> It's not too late to release 0.9.2 with these API changes Romain> and encourage people not to use 0.9.1... If it happens this week, I'm fine with that. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON |

Re: [tcpdump-workers] tcpdump 3.9.1 under Windows

2005-07-06 Thread Michael Richardson
ersion of WinDump with a small patch in the dsp. I expect a 3.9.2/0.9.2 to go out on Sunday, if we can do that. Please pull up what you need to the branch. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec

[tcpdump-workers] 0.9.2/3.9.2

2005-07-10 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Any objection to 0.9.2 going out in the next 20 hours? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr

Re: [tcpdump-workers] 0.9.2/3.9.2

2005-07-11 Thread Michael Richardson
ready. So you are happy with what is on the branch? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http://www.sandelman.ca/mcr/www.xelerance.com/training/ |device driv

[tcpdump-workers] release 0.9.2/3.9.2

2005-07-11 Thread Michael Richardson
1044 %md5sum *.tar.gz 36d310c1266e6e6a34295c2e0afd3e10 libpcap-0.9.2.tar.gz 65dcb4d5eff136f66a221416cb1c2054 tcpdump-3.9.2.tar.gz - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect

  1   2   3   4   5   6   7   >