Wireshark-bugs: [Wireshark-bugs] [Bug 3560] USB Packets in pcap-ng Files Not Dissected Properly
Date: Wed, 17 Sep 2014 18:03:59 +0000

Comment # 14 on bug 3560 from
Hi Guy,

Sorry for the late response. 

It's been such a long time ago since I prepared these capture files, that I'm
not 100% sure - but I suspect that it was using a fairly early version of
mergecap, during the period where pcap-ng support was still in "experimental"
state.

If I remember correctly, the Apple IP-over-1394 "trace" was generated using
text2pcap from a hex dump that I found in a blog post - and then, in hindsight,
it seems that it didn't have complete packet headers.

Apologies that I can't be much more helpful than that,

Tyson.

(In reply to Guy Harris from comment #13)
> (In reply to Tyson Key from comment #6)
> > Created attachment 3164 [details]
> > New version of the usbmon0 ntar capture, to make things easier (converted
> > version of 3163)
> 
> Converted in what fashion?  It looks really badly mangled in top-of-trunk
> Wireshark.


You are receiving this mail because:
  • You are the assignee for the bug.
  • You are watching all bug changes.