It is framed with escape characters. The ethereal can recognize the PPPdump format? Otherwise what should I do next? Binary Chen
________________________________ From: [EMAIL PROTECTED] 代表 Guy Harris Sent: 2005-12-6 (星期二) 10:00 To: tcpdump-workers@lists.tcpdump.org Subject: Spam:Re: [tcpdump-workers] libpcap for PPP raw data problem (Sent from the wrong address, so it bounced; resent from the right address, with extra crud added so that it doesn't get bounced again as a duplicate message.) On Dec 4, 2005, at 8:37 PM, BinaryChen(TP/SH) wrote: > I have captured some raw PPP data from serial driver, and I want > use libpcap to convert to pcap file format so the ethereal can help > me do some analyze. Can anyone provide some sample or hints to me? The first hint is that if it's truly *raw* data - i.e., it's just two streams of bytes going to and from the host, not divided into frames, and with the framing and escape bytes in the stream - you'd probably be better off putting it in pppdump format, which is the format that pppd writes out. See the comments in Ethereal's wiretap/pppdump.c to see what that format is like. - This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.
<<winmail.dat>>
- This is the tcpdump-workers list. Visit https://lists.sandelman.ca/ to unsubscribe.