It is framed with escape characters.
 
The ethereal can recognize the PPPdump format? Otherwise what should I do next?
 
Binary Chen

________________________________

From: [EMAIL PROTECTED] 代表 Guy Harris
Sent: 2005-12-6 (星期二) 10:00
To: tcpdump-workers@lists.tcpdump.org
Subject: Spam:Re: [tcpdump-workers] libpcap for PPP raw data problem



(Sent from the wrong address, so it bounced; resent from the right 
address, with extra crud added so that it doesn't get bounced again 
as a duplicate message.)

On Dec 4, 2005, at 8:37 PM, BinaryChen(TP/SH) wrote:

> I have captured some raw PPP data from serial driver, and I want 
> use libpcap to convert to pcap file format so the ethereal can help 
> me do some analyze. Can anyone provide some sample or hints to me?

The first hint is that if it's truly *raw* data - i.e., it's just two 
streams of bytes going to and from the host, not divided into frames, 
and with the framing and escape bytes in the stream - you'd probably 
be better off putting it in pppdump format, which is the format that 
pppd writes out.  See the comments in Ethereal's wiretap/pppdump.c to 
see what that format is like.
-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.


<<winmail.dat>>

-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.

Reply via email to