Re: [tcpdump-workers] release 0.9.2/3.9.2

2005-07-11 Thread Michael Richardson
Romain> where it should say "Summary for 0.9.x release", or Romain> something. Romain> Looks great otherwise! Oops. marajade-[/mara7/tcpdump/3.9] mcr 1061 %md5sum *.tar.gz 30a9ec79265127f2a2153498ef58bd54 libpcap-0.9.2.tar.gz 6dac4e01a005cc22904f5a7d3c69f769 t

[tcpdump-workers] 3.9.x

2005-07-13 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Do I re-release 3.9.2 with the windows patches, or do 3.9.3? I haven't PGP signed anything, or updated the web site yet. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing

Re: [tcpdump-workers] print-slow.c

2005-07-14 Thread Michael Richardson
, it should Guy> include a person with both MSVC++ and Cygwin (and MinGW32?) Guy> development environments. -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IPsec training, see |net architect[ ] http

Re: [tcpdump-workers] 3.9.x

2005-07-14 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- I will do a new 3.9.3, and sign it. Numbers are cheap. marajade-[/mara7/tcpdump/3.9] mcr 1057 %md5sum *.9.3.tar.gz 0ad921c881fdd3d278046afcd352a151 libpcap-0.9.3.tar.gz 26c2f6405d6a94f1160a83109b2f71dd tcpdump-3.9.3.tar.gz Web site updated. - -- ] Michael

Re: [tcpdump-workers] 3.9.x

2005-07-15 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- >>>>> "Romain" == Romain Francoise <[EMAIL PROTECTED]> writes: >> I will do a new 3.9.3, and sign it. Romain> The VERSION files are still at x.9.2... Sigh. Sorry. I'm not going to fix this. Let's

Re: [tcpdump-workers] Pings fail unless tcpdump is watching both

2005-08-17 Thread Michael Richardson
NIC, SOME drivers invisibly put the NIC into Burton> promiscuous mode (so they can do the multiple-ip filtering) Burton> and do not report same to the kernel. I think that you mean, multiple MACs ? - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ]

Re: [tcpdump-workers] 0.9.4/3.9.4 release?

2005-08-18 Thread Michael Richardson
41453516 672529 ../htdocs/beta/tcpdump-3.9.4-230.tar.gz Please verify my sanity, I just pushed the button. The files may need to have Changes, etc. done to them. - -- ] Michael Richardson Xelerance Corporation, Ottawa, ON | firewalls [ ] mcr @ xelerance.com Now doing IP

Re: [tcpdump-workers] 0.9.4/3.9.4 release?

2005-08-19 Thread Michael Richardson
tcpdump for additional Juniper Guy> link-layer types. Hannes> i have not yet done the printers for those (but that should Hannes> be straightforward) can you give me the weekend to complete Hannes> those, pls ? yes. -- ] Michael Richardson Xelerance

Re: [tcpdump-workers] Spelling fixes

2005-09-02 Thread Michael Richardson
man. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"

[tcpdump-workers] [tcpdump-announce] tcpdump 3.9.4

2005-10-03 Thread Michael Richardson
ar.gz) = 4b64755bbc8ba1af49c747271a6df5b8 I hope the version is correct this time, and I think that all the pull ups have been done properly. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROT

[tcpdump-workers] www.tcpdump.org

2005-10-12 Thread Michael Richardson
. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel ha

[tcpdump-workers] downtown for cvs

2005-11-16 Thread Michael Richardson
firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -BEGIN PGP SIGNATURE- Version: Gnu

Re: [tcpdump-workers] where to get libpcap-ng?

2006-01-11 Thread Michael Richardson
: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy

Re: [tcpdump-workers] where to get libpcap-ng?

2006-01-12 Thread Michael Richardson
7;t have to work around bugs in older versions of ntar in pcap. Downside: file capture format and packet capture mechanism are not inheirently related. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation,

Re: [tcpdump-workers] Multi process sniffing and dropped packets

2006-01-12 Thread Michael Richardson
kernel returns one-packet-per-read (some mmap'ed interfaces do not!), then you should get pretty good round-robin performance. Since you are fork()'ing you have no thread issues. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michae

[tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
This is another test of the mailing list. - This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.

Re: [tcpdump-workers] testing the list

2006-02-16 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >>>>> "Michael" == Michael Richardson <[EMAIL PROTECTED]> writes: Michael> This is another test of the mailing list. I don't know what I did wrong. But, it is fixed now. A kind gentleman was doing th

[tcpdump-workers] tcpdump.org

2006-02-16 Thread Michael Richardson
r high. (1 userids @tcpdump.org, continuously hit from 5-10 hosts, greylisting has minimal effect, since I 451 things I won't relay) - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net

[tcpdump-workers] (slightly off-topic) looking for liveCD based packet generator

2006-06-19 Thread Michael Richardson
o err is human. To moo, bovine. | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"

[tcpdump-workers] installing tcpdump with a version number

2006-06-19 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have various scripts and regression test cases that depend upon specific versions of tcpdump. So, I often install it with a version number as well. I install it twice. Alternatively, a symlink could be changed. This no doubt would mess up packaging

[tcpdump-workers] [tcpdump-announce] tcpdump and libpcap x.9.5 released

2006-09-19 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thanks to Ken Bantoft for updating the CHANGES file. marajade-[/mara7/tcpdump/3.9/f] mcr 1153 %sha1sum *.tar.gz 3a3b0821f7201b4a72201c69ca2411a3db8a83c3 libpcap-0.9.5.tar.gz a9850177809196008ed3e6212cb651ed1500353c tcpdump-3.9.5.tar.gz http://www.

Re: [tcpdump-workers] What's happening with www.tcpdump.org?

2006-09-27 Thread Michael Richardson
Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, s

Re: [tcpdump-workers] [PATCH] enable sniff on USB ports on linux

2006-09-28 Thread Michael Richardson
Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security gu

Re: [tcpdump-workers] [RESEND][PATCH] enable sniff on USB ports on linux (BSD license)

2006-10-02 Thread Michael Richardson
quot; being just I concur. >> I have to fix also the dlt issue. Can you please assign a new DLT >> value for me ? Guy> I've added DLT_USB, with a value of 186. Stupid me... is this for IP over USB, or is it for something weirder, like treating SCSI over USB

Re: [tcpdump-workers] [RESEND][PATCH] enable sniff on USB ports

2006-10-04 Thread Michael Richardson
: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, sec

Re: [tcpdump-workers] problem with relay server using pcap

2006-10-11 Thread Michael Richardson
are duplicating the packets? - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] pani

Re: [tcpdump-workers] I would like to 'request a link- layer type value for WiMax'

2006-11-08 Thread Michael Richardson
ial Way East Cruz> Eatontown, NJ 07724 Cruz> 732-935-5393 Cruz> cruz_petagay mailto:[EMAIL PROTECTED]> @bah.com - -- ] Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|n

Re: [tcpdump-workers] sniffing from USB bus: current shortcoming

2006-11-28 Thread Michael Richardson
just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy&quo

Re: [tcpdump-workers] USB support in libpcap

2007-03-26 Thread Michael Richardson
f the point is to do a network capture from a USB attached wifi, why not just capture the 802.11 frames themselves into the already standardized frame formats we have? - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,

Re: [tcpdump-workers] [Wireshark-users] Filtering both vlan-tagged as untagged frames with an ip-filter

2007-05-02 Thread Michael Richardson
ts own manpage Joerg> and into the libpcap package be acceptable? If so, I'm Joerg> willing to produce one. I don't think the syntax should go into pcap(3). If you want to create a new man page, I think that's reasonable. - -- ] Bear: "

Re: [tcpdump-workers] tcpdump v3.9.6 archive incorrect version ?

2007-07-09 Thread Michael Richardson
]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/L

Re: [tcpdump-workers] Patches for wlan filtering

2007-07-10 Thread Michael Richardson
ring.patch I was not able to apply it to either HEAD or 3.9.6. All hunk's failed. Can you double check that you tried applying to 1.284 of libpcap/gencode.c? - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,X

Re: [tcpdump-workers] Patches for wlan filtering

2007-07-10 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Oh, stupid me. I see the patch is already applied by you. I read the dates wrong while searching for it... - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corp

[tcpdump-workers] removing weeklies

2007-07-23 Thread Michael Richardson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is there any objection to removing weekly tar balls from http://www.tcpdump.org/weekly/ that are more than 1 year older than the last release? - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls

[tcpdump-workers] [tcpdump-announce] version 3.9.7

2007-07-23 Thread Michael Richardson
ar.gz 0e2e494d8a66dd644fff03dcad7887164aef9b0e libpcap-0.9.7.tar.gz 5d2a95f0de1cbae70ba01c64f9a2c0fac0183dba tcpdump-3.9.7.tar.gz - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL

Re: [tcpdump-workers] Announce: tcpdump 3.9.8 and libpcap 0.9.8 released

2007-10-01 Thread Michael Richardson
ideally, a make and a make test. Unfortunately, it also encourages one to do a release from a dirty directory. Suggestions...? - -- ] Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net a

[tcpdump-workers] change of IP for bpf.tcpdump.org

2007-10-31 Thread Michael Richardson
ot;Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel h

Re: [tcpdump-workers] change of IP for bpf.tcpdump.org

2007-11-01 Thread Michael Richardson
n CA through Gianluca> AT&T/SBC. Sorry, internal routing problem, and it's resolved now. Gianluca> hsa-sandleman-software-works.storm.ca [209.87.254.158] 18 -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,

Re: [tcpdump-workers] Changes to the web-page

2007-11-07 Thread Michael Richardson
I agree with Luis> you, it would be nice if those reports were also sent to the Luis> list. Is this possible? The problem is spam. The list machine is not the CVS/web server, so the archives have to be copied manually. -- ]Bear: "Me, I'm just the shape of

Re: [tcpdump-workers] About some libpcap patches

2007-11-15 Thread Michael Richardson
t explaining what and why. - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/mcr/ |device driver[ ] panic("

Re: [tcpdump-workers] tcpdump in c programm

2007-11-18 Thread Michael Richardson
ch you can link directly. It will take a pcap source, and will produce output to a fprintf-like function (which could be a string append function for another program). This is a work in-progress. - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [

Re: [tcpdump-workers] tcpdump patches...

2007-12-09 Thread Michael Richardson
to verify that -P and -Z aren't going to horribly clash with some unpublished (i.e. "distro") patches. - -- ]Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ ]

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-13 Thread Michael Richardson
don't see a reason to have this array of pcap_opthdr. - -- ] Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-13 Thread Michael Richardson
_prop() on the pt too. Adding functions that act on a handle is a very nice way to extend an interface. - -- ] Bear: "Me, I'm just the shape of a bear." | firewalls [ ] Michael Richardson,Xelerance Corporation, Ottawa, ON|net architect[ [EMAIL PROTEC

Re: [tcpdump-workers] supporting extend 'open live capture' parametes

2008-01-14 Thread Michael Richardson
I would like to try to implement the new API this way and Abeni> post some code, even in very experimental form, in the hope Abeni> to make the discussion/analysis easier (at least to Abeni> me...). What do you think? I think it's a great idea. -- ] Bear:

Re: [tcpdump-workers] Web site down

2008-03-28 Thread Michael Richardson
I will take a look at it. You may find a mirror is still alive: www.br.tcpdump.org, www.jp.tcpdump.org etc. - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.

Re: [tcpdump-workers] [Patch] tcpdump probabilistic sampling

2008-04-02 Thread Michael Richardson
Only... -P is used somewhere else, in another patch, I think. We gotta get 4.0 out, with long options... - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.

Re: [tcpdump-workers] Libpcap 1.0, WinPcap and documentation

2008-04-10 Thread Michael Richardson
o the Gianluca> CVS when pcap.h gets updated. Or (3rd option) I will just I don't have a problem with committed the result of doxygen update. pcap.h doesn't change that often, so the average user will not need it. -- ] ON HUMILITY: to err is human. To moo, bovine.

Re: [tcpdump-workers] [Patch] tcpdump probabilistic sampling

2008-04-14 Thread Michael Richardson
>>>>> "Guy" == Guy Harris <[EMAIL PROTECTED]> writes: Guy> Michael Richardson wrote: >> Only... -P is used somewhere else, in another patch, I think. We >> gotta get 4.0 out, with long options... Guy> tcpdump currently still u

[tcpdump-workers] mirrors

2008-06-23 Thread Michael Richardson
oes not answer right now. remove? www.my leads to broken system, removed. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] h

[tcpdump-workers] bpf.tcpdump.org

2008-06-24 Thread Michael Richardson
. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ - This is t

Re: [tcpdump-workers] mirrors

2008-06-24 Thread Michael Richardson
fter an upgrade to solve a libc vs TLS issue. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("

[tcpdump-workers] bpf down

2008-07-22 Thread Michael Richardson
my day job. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using,

Re: [tcpdump-workers] tcpdump.org/release/ is down

2008-09-02 Thread Michael Richardson
find tapes without being in the same building, which I'm not right now) -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |dev

Re: [tcpdump-workers] Capturing without having superuser rights

2008-10-14 Thread Michael Richardson
is. One some systems, (Solaris? BSD?) a chown/chgrp/chmod on some magic /dev file does the trick, on others (Linux), I don't think there is a way to avoid root. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richards

Re: [tcpdump-workers] tcpdump 4.0.0rc2 and libpcap 1.0.0rc2 now available

2008-10-16 Thread Michael Richardson
Thanks Guy for bringing the shared object support in. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-10-16 Thread Michael Richardson
etf.org/html/rfc4288) is the latest doctrine on getting media types, and basically, we post to [EMAIL PROTECTED] As for a specification document, pcap.h is basically it. We would be a vendor type. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-10-23 Thread Michael Richardson
uldn't get added to Reply-To: That would be a neat feature. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-10-23 Thread Michael Richardson
THANK YOU! -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, ke

Re: [tcpdump-workers] tcpdump 4.0.0rc3 and libpcap 1.0.0rc3 now available

2008-10-27 Thread Michael Richardson
I tried building the library before signing it: marajade-[Misc/tcpdump/4.0/libpcap-1.0.0] mcr 1039 %make gcc -O2 -fPIC -I. -DHAVE_CONFIG_H -D_U_="__attribute__((unused))" -c ./pcap-linux.c ./pcap-linux.c: In function 'pcap_read_packet': ./pcap-linux.c:653: error: invalid application of 'sizeof

[tcpdump-workers] git repo

2008-11-05 Thread Michael Richardson
ux.c:46:22: error: pcap/usb.h: No such file or directory It might be that I'm missing some pieces/branches. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL

Re: [tcpdump-workers] libpcap-1.0.0 sita configure check

2008-11-05 Thread Michael Richardson
ixes this issue. Applied to new git tree. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Jus

[tcpdump-workers] --disable-ipv6 and git trees

2008-11-07 Thread Michael Richardson
I've learnt that the git-cvsimport did not do a complete job. I will import additional things tonight. I did not get any feedback about moving to git. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Otta

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-09 Thread Michael Richardson
#define DLT_EVDEV_LINUX DLT_EVDEV when we get a request for a similar, but incompatible event system. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.s

Re: [tcpdump-workers] tcpdump-4.0.0: disable automatic dependency on libsmi

2008-11-09 Thread Michael Richardson
which allows to disable it. Patch applied. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just anothe

[tcpdump-workers] git trees

2008-11-09 Thread Michael Richardson
bonus. github is now updated nightly at 1:23am. - -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Ju

Re: [tcpdump-workers] git trees

2008-11-10 Thread Michael Richardson
mon at: git://bpf.tcpdump.org/{tcpdump,libpcap} and at github, updated nightly. I updated the tcpdump_current (daily snapshots) to pull from git. -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-13 Thread Michael Richardson
efine DLT_LINUX_EVDEV 216 What else should I write? -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] p

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-14 Thread Michael Richardson
point. http://github.com/mcr/libpcap/commit/bfb8369657376d58ff54a4a0e64adc86900c2327 -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/

Re: [tcpdump-workers] git repo

2008-11-15 Thread Michael Richardson
>>>>> "Guy" == Guy Harris <[EMAIL PROTECTED]> writes: Guy> Unless I'm missing something, a lot of the history seems to Guy> have gotten lost. For example, "git log pcap-bpf.c" shows: >> commit a9ff5b3dcf3eb90f519c70b4

Re: [tcpdump-workers] Linux input layer evdev capturing

2008-11-17 Thread Michael Richardson
] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] [EMAIL PROTECTED] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, se

Re: [tcpdump-workers] tcpdump manpage

2008-11-28 Thread Michael Richardson
s a BSD 3-clause license on it. So, you can. (Speaking of BSD n-clause licenses... I think we did determine that we should be able to remove clause 3 everywhere) -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON

Re: [tcpdump-workers] tcpdump400 compile pb without ipv6 (print-enc.c)

2008-12-01 Thread Michael Richardson
I am tempted to simply import each major release as a branch in git. It will have no common ancestry unless I import it against the branch point. Comments? -- ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-12-11 Thread Michael Richardson
>>>>> "Phil" == Phil Vandry writes: Phil> We suggest that the type should be "application/libpcap-capture" and application/pcap-capture makes more sense to me. -- ] Y'avait une poule de jammé dans l'muffler!!!!!|

Re: [tcpdump-workers] MIME type for libpcap-format capture files

2008-12-11 Thread Michael Richardson
>>>>> "Phil" == Phil Vandry writes: >> On Dec 11, 2008, at 12:26 PM, Michael Richardson wrote: >> >> > application/pcap-capture Phil> [...] >> 3) not all pcap-format files are written by libpcap. Phil> ..

[tcpdump-workers] Darren Reed: Improving the data supplied by BPF

2008-12-29 Thread Michael Richardson
This is a thread from tech-...@netbsd.org: http://article.gmane.org/gmane.os.netbsd.devel.network/10476 --- Begin Message --- Recently I've talked with a few different folks about packet capture and have become aware of some of the problems that people face when trying to use BPF vs other propr

Re: [tcpdump-workers] Migrating to git

2009-01-02 Thread Michael Richardson
ump.org/tcpdump/master/git/tcpdump -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(&q

Re: [tcpdump-workers] libpcap build problem

2009-01-24 Thread Michael Richardson
ror. Tron> This occurs because Tron> pcap-linux.c includes the file /usr/include/net/if.h and then Tron> includes the file Where does /usr/include/net/if.h on slackware come from? glibc? kernel? - -- ] Y'avait une poule de jammé dans l'muffler!!!!!| fi

Re: [tcpdump-workers] Where to get tcpslice?

2009-02-06 Thread Michael Richardson
, send ssh key. I think you'd become the tcpsplice prime :-) -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ott

Re: [tcpdump-workers] question about -E parameter decrypting esp packets

2009-02-19 Thread Michael Richardson
d extensively by the Openswan KLIPS regression testing system, which is part of every source tree, if you want more examples than are in tcpdump/tests - -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Otta

Re: [tcpdump-workers] question about -E parameter decrypting esp packets

2009-02-20 Thread Michael Richardson
, one could work around that problem, but the default capture length probably doesn't include any ciphertext... - -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m.

Re: [tcpdump-workers] Should the default snapshot length in tcpdump be 65535?

2009-02-21 Thread Michael Richardson
use libnetdissect, and start anew option-wise. We have lots of overlapping and confusing option letters on tcpdump. It would be tcpdump with a different main(). -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Soft

Re: [tcpdump-workers] Hardware mac address with pcap/winpcap

2009-03-03 Thread Michael Richardson
de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"

Re: [tcpdump-workers] patch to allow tcpslice to work with zero and one packet captures

2009-03-25 Thread Michael Richardson
Yes, we do take patches for tcpslice. Sam, please send GPG signed SSH key, and we can move the CVS into git... The CVS isn't gone, it's just not primary. -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman So

Re: [tcpdump-workers] Unable to build tcpdump 4.0.0 [Debian 2.6.26-2 - libpcap 1.0.0]

2009-04-30 Thread Michael Richardson
] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, se

Re: [tcpdump-workers] Pull request : pcap-dag

2009-05-06 Thread Michael Richardson
l'muffler! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy&quo

Re: [tcpdump-workers] self-made pcap_t struct

2009-05-10 Thread Michael Richardson
Please see uml_netjig from the Openswan tree: testing/utils/uml_netjig. http://git.openswan.org/ (but the browse has a problem) http://github.com/mcr/bluerose/tree/60f2d2b0dd22f9b7fc0e7255d77be8abec030b7a/testing/utils/uml_netjig I tried multiple times over the years to get this program (which i

Re: [tcpdump-workers] request for new DLT type

2009-05-12 Thread Michael Richardson
Date: Mon, 11 May 2009 11:18:30 -0500 * * DLT_AOS. We need it for AOS Space Data Link Protocol. * I have already written dissectors for but need an OK from * legal before I can submit a patch. * */ #define DLT_AOS 222 -- ] Y'avait une poule de jammé dans l'm

Re: [tcpdump-workers] Problems with select (the other way around...)

2009-05-15 Thread Michael Richardson
gument to select is the highest FD that you want to look at. Essentially, this sizes the bitfields ("fdsets"). " nfds is the highest-numbered file descriptor in any of the three sets, plus 1. " so, you need to set it to "handle_fd + 1" -- ]

Re: [tcpdump-workers] vlan [xx] filter not filtering any packets

2009-06-08 Thread Michael Richardson
dded. I suspect that the vlan filter may not work if there is further SNAP headers, but that's just top of my head idea.. -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net arc

Re: [tcpdump-workers] "stream" data from tcpdump

2009-07-17 Thread Michael Richardson
s the original tcpdump. have a tool that implements your pcap filter, and opens some fifos/unix sockets, and write pcap format to it. tcpdump -r option does not seek, so you can read from a pipe with it. -- ] Y'avait une poule de jammé dans l'muffler!| firewalls

Re: [tcpdump-workers] Any chance of getting tcpdump 4.0.1/libpcap 1.0.1 out?

2009-07-21 Thread Michael Richardson
.1 sooner, I'm all for it. What is your schedule? When is soon enough? -- ] Y'avait une poule de jammé dans l'muffler!| firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.s

[tcpdump-workers] bpf.tcpdump.org

2009-08-24 Thread Michael Richardson
The machine bpf.tcpdump.org will be down today so that the VM can be copied to another machine. I expect it to take 3-4 hours, and I'll bring it up, and adjust DNS tonight. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sand

[tcpdump-workers] tcpdump.org mirrors

2009-08-24 Thread Michael Richardson
machine responds to www.tcpdump.org. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just

Re: [tcpdump-workers] tcpdump.org mirrors

2009-08-25 Thread Michael Richardson
>>>>> "Michael" == Michael Richardson writes: Michael> The data transfer of the bpf.tcpdump.org is still underway, Michael> and should complete by morning EST. cvs.tcpdump.org, bpf.tcpdump.org and www.tcpdump.org are online again. It seems tha

Re: [tcpdump-workers] tcpdump.org mirrors

2009-08-26 Thread Michael Richardson
sync://bpf.tcpdump.org/htdocs/ Thank you for the mirror offer. I've put it into the zone file. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca htt

Re: [tcpdump-workers] [PATCH 1/3] Add getnameinfo support to getname and getname6.

2009-08-30 Thread Michael Richardson
Sorry to take so long. Did you get any other reply yet? -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device

[tcpdump-workers] bpf.tcpdump.org

2009-09-01 Thread Michael Richardson
this issue, or also fails to notice that the machine doesn't go offline now and then. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca

Re: [tcpdump-workers] website offline?

2009-09-16 Thread Michael Richardson
>>>>> "Darren" == Darren Reed writes: Darren> I'm seeing this Sorry. One machine had the wrong IP in it's virtualhost definition. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandel

Re: [tcpdump-workers] website offline?

2009-09-16 Thread Michael Richardson
feel that an A record is in order, I might agree. -- ] He who is tired of Weird Al is tired of life! | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON|net architect[ ] m...@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic(&qu

<    1   2   3   4   5   6   7   >