wireshark.org protocol dissector with Osmocom additions
Go to file
Guy Harris ae53260d02 Keep in the "wtap" structure the current offset into the file being
read, and maintain it ourselves as we read through the file, rather than
calling "ftell()" for every packet we read - "ftell()" may involve an
"lseek()" call, which could add a noticeable CPU overhead when reading a
large file.

svn path=/trunk/; revision=596
1999-08-28 01:19:45 +00:00
doc Changed packet-tr.c to insert tr.sr, a FT_BOOLEAN field, only if tr.sr 1999-08-27 19:27:22 +00:00
gtk Touched these files to make 'make dist' happy. 1999-08-27 23:39:32 +00:00
image * Added column formatting functionality. 1998-11-17 04:29:13 +00:00
wiretap Keep in the "wtap" structure the current offset into the file being 1999-08-28 01:19:45 +00:00
AUTHORS Fix the e-mail address for Jeff Foster. 1999-08-20 21:57:29 +00:00
COPYING * Copied in the correct GNU license (I'm such a goober) 1998-10-16 01:18:35 +00:00
ChangeLog Initial revision 1998-09-16 02:39:15 +00:00
INSTALL Updated docs. 1999-08-27 22:57:56 +00:00
INSTALL.configure * Installation documentation updates 1998-12-29 03:12:07 +00:00
Makefile.am Added gtk subdirectory, with patched gtkclist.c in it. We can use this 1999-08-27 22:27:18 +00:00
Makefile.nmake Put "packet-atm.c" in. 1999-08-22 07:10:08 +00:00
NEWS Updated docs. 1999-08-27 22:57:56 +00:00
README Updated docs. 1999-08-27 22:57:56 +00:00
README.tru64 Miscellaneous updates of README and README.tru64 created. 1999-04-30 21:16:31 +00:00
README.win32 Finally got the win32 ethereal to link properly with MSVC. 1999-07-21 17:40:42 +00:00
acconfig.h Added the ability to create a read-only ethereal, i.e., one that 1999-07-09 04:18:36 +00:00
acinclude.m4 Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
alignment.h Get rid of the "P*" macros, as we're not using them (Ethereal only reads 1999-05-10 20:17:36 +00:00
autogen.sh Added gtk subdirectory, with patched gtkclist.c in it. We can use this 1999-08-27 22:27:18 +00:00
capture.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
capture.h Re-arranged Ethereal's definitions of DLT_RAW et al. since capture.c 1999-08-18 16:28:22 +00:00
colors.c "read_filters()" is actually called late enough in the startup process 1999-08-25 03:22:46 +00:00
colors.h Added John McDermott's colorization routines. There's still some 1999-08-24 16:27:23 +00:00
column.c Fix up the comment before "get_column_width()" to reflect current 1999-07-28 03:47:03 +00:00
column.h Have: 1999-07-28 03:29:02 +00:00
config.guess * Scripts needed for configure.in 1998-09-20 00:25:16 +00:00
config.h.win32 Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
configure.in Added gtk subdirectory, with patched gtkclist.c in it. We can use this 1999-08-27 22:27:18 +00:00
dfilter-grammar.y Changed packet-tr.c to insert tr.sr, a FT_BOOLEAN field, only if tr.sr 1999-08-27 19:27:22 +00:00
dfilter-int.h The dfilter yacc grammar now keeps track of every GNode that it allocates. 1999-08-26 06:20:50 +00:00
dfilter-scanner.l Changed packet-tr.c to insert tr.sr, a FT_BOOLEAN field, only if tr.sr 1999-08-27 19:27:22 +00:00
dfilter.c The dfilter yacc grammar now keeps track of every GNode that it allocates. 1999-08-26 06:20:50 +00:00
dfilter.h The dfilter yacc grammar now keeps track of every GNode that it allocates. 1999-08-26 06:20:50 +00:00
display.c Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
display.h Added "Capture" and "Display" menus; "Capture" has a "Start" item, which 1999-06-19 01:14:51 +00:00
ethereal.c The dfilter yacc grammar now keeps track of every GNode that it allocates. 1999-08-26 06:20:50 +00:00
ethereal.h DLT_NULL, from "libpcap", means different things on different platforms 1999-08-22 00:47:56 +00:00
ethereal.spec.in Changed spec file for producing RPMs to ethereal.spec.in so that 1999-08-24 17:18:35 +00:00
ethertype.c Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
etypes.h Add a comment. 1999-08-22 01:35:34 +00:00
file.c Introduces a new global gboolean variable: proto_tree_is_visible. 1999-08-26 07:01:44 +00:00
file.h Added John McDermott's colorization routines. There's still some 1999-08-24 16:27:23 +00:00
filter.c Since ethereal is now dependent on GTK+-1.2.x (because of proto_tree and 1999-07-13 03:08:06 +00:00
filter.h * Pod page update 1998-10-13 02:10:57 +00:00
follow.c Fix TCP follow stream feature: 1999-07-31 13:55:16 +00:00
follow.h Fix TCP follow stream feature: 1999-07-31 13:55:16 +00:00
gtkpacket.c Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
gtkpacket.h Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
manuf *** empty log message *** 1998-09-27 07:13:29 +00:00
menu.c Added John McDermott's colorization routines. There's still some 1999-08-24 16:27:23 +00:00
menu.h Since ethereal is now dependent on GTK+-1.2.x (because of proto_tree and 1999-07-13 03:08:06 +00:00
packet-aarp.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-arp.c The protocol tree field created for a protocol itself is of type 1999-07-30 05:42:25 +00:00
packet-atalk.c Declare the "packet_info" structure "pi" in "packet.h", rather than in a 1999-08-18 00:57:54 +00:00
packet-atm.c Add support for reading Full Frontal ATM from an ATM Sniffer capture 1999-08-20 06:55:20 +00:00
packet-bootp.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-cdp.c Instead of adding the TLV type and length values as hidden values, enter 1999-08-25 00:42:49 +00:00
packet-clip.c In the summary display for CLIP frames, make the protocol CLIP (which 1999-08-24 06:16:27 +00:00
packet-data.c Properly pluralize "bytes" in the detail line for "dissect_data()". 1999-08-26 17:51:44 +00:00
packet-dns.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-dns.h Correctly handle the case of the root showing up as a name in a DNS 1999-05-27 05:35:08 +00:00
packet-eth.c In the summary display for Ethernet frames, make the protocol Ethernet 1999-08-24 06:10:05 +00:00
packet-fddi.c More completely decode the frame control field of an FDDI frame. 1999-08-24 06:01:45 +00:00
packet-ftp.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-giop.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-gre.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-http.c Fix a typo in "Hypertext". 1999-07-30 00:57:15 +00:00
packet-icmpv6.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-ip.c Dissect unknown IP protocols with dissect_data(). 1999-08-26 17:31:37 +00:00
packet-ip.h Added RSVP protocol dissector. 1999-06-11 16:45:02 +00:00
packet-ipsec.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-ipv6.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-ipv6.h Got rid of ipv6 compiler warnings when compiling on RedHat 6.0. 1999-07-23 15:08:25 +00:00
packet-ipx.c Changed the display filter scanner from GLIB's GScanner to lex. The code 1999-08-01 04:28:20 +00:00
packet-ipx.h I've started to figure out the difference between NetBIOS over IPX for 1998-10-14 05:18:32 +00:00
packet-isakmp.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-lapb.c Add support for reading Full Frontal ATM from an ATM Sniffer capture 1999-08-20 06:55:20 +00:00
packet-llc.c Have "get_xdlc_control()" and "dissect_xdlc_control()" just return a 1999-08-23 23:24:36 +00:00
packet-lpd.c Use END_OF_FRAME rather than "fd->cap_len - offset" - END_OF_FRAME used 1999-08-25 17:38:36 +00:00
packet-nbipx.c NBIPX packet type 3 appears to be the equivalent, in NBIPXland, of the 1999-08-25 01:36:21 +00:00
packet-nbns.c Move the code to set "max_data" in "dissect_nbss()" earlier, so that 1999-08-21 17:59:36 +00:00
packet-ncp.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-ncp.h Re-wrote the NCP module in accordance with how NCP is really organized. 1999-03-20 04:38:57 +00:00
packet-netbios.c Fixed the array problem in packet-netbios. 1999-08-24 22:36:34 +00:00
packet-nntp.c Declare the "packet_info" structure "pi" in "packet.h", rather than in a 1999-08-18 00:57:54 +00:00
packet-null.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-osi.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-ospf.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-ospf.h Removed all references to gtk objects from packet*.[ch] files. They now 1999-03-23 03:14:46 +00:00
packet-pop.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-ppp.c Add in the Async Map option. 1999-08-25 07:32:46 +00:00
packet-pppoe.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-pptp.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-radius.c Checked in Johan's Updated RADIUS dissector which uses the new proto_tree 1999-08-03 14:59:16 +00:00
packet-raw.c Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
packet-rip.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-rip.h The address family isn't part of the RIP header, it's part of the RIP 1998-11-20 09:24:42 +00:00
packet-rsvp.c Updated RSVP decoder with Ashok's newest code. 1999-08-27 19:21:36 +00:00
packet-rsvp.h "long" -> "gint32" ("gint32" is 32 bits, "long" isn't necessarily 32 1999-08-27 20:10:14 +00:00
packet-rtsp.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-sdp.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-smb.c Convert a bunch of uses of "fd->cap_len" to use "pi.captured_len" (or to 1999-08-26 07:34:43 +00:00
packet-snmp.c Call "init_mib()" in "proto_register_snmp()"; not doing so causes core 1999-08-20 21:26:37 +00:00
packet-tcp.c Fix up the call to "reassemble_tcp()" to use "pi.len" and 1999-08-18 03:11:14 +00:00
packet-telnet.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
packet-tftp.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-tr.c Changed packet-tr.c to insert tr.sr, a FT_BOOLEAN field, only if tr.sr 1999-08-27 19:27:22 +00:00
packet-trmac.c Made the protocol (but not the fields) use the new proto_tree routine, 1999-07-29 05:47:07 +00:00
packet-udp.c Declare the "packet_info" structure "pi" in "packet.h", rather than in a 1999-08-18 00:57:54 +00:00
packet-vines.c Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
packet-vines.h * Added Joerg Mayer's Vines patch 1998-12-29 04:05:38 +00:00
packet-x25.c Add support for reading Full Frontal ATM from an ATM Sniffer capture 1999-08-20 06:55:20 +00:00
packet.c Add a new Wiretap encapsulation type WTAP_ENCAP_FDDI_BITSWAPPED, meaning 1999-08-24 03:19:34 +00:00
packet.h Add in the Async Map option. 1999-08-25 07:32:46 +00:00
prefs.c Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
prefs.h Add a "File/Print" menu item, which prints *all* the packets in the 1999-07-23 08:29:24 +00:00
print.c Printing multiple frames in PostScript is a bit tricky, I think - I 1999-07-23 21:09:25 +00:00
print.h Printing multiple frames in PostScript is a bit tricky, I think - I 1999-07-23 21:09:25 +00:00
print.ps * Added Joerg Mayer's Vines patch 1998-12-29 04:05:38 +00:00
proto.c Introduces a new global gboolean variable: proto_tree_is_visible. 1999-08-26 07:01:44 +00:00
proto.h Introduces a new global gboolean variable: proto_tree_is_visible. 1999-08-26 07:01:44 +00:00
ps.h Added ID tags to the beginning of each source file. 1998-09-16 03:22:19 +00:00
rdps.c Finally got the win32 ethereal to link properly with MSVC. 1999-07-21 17:40:42 +00:00
resolv.c Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
resolv.h Created a new protocol tree implementation and a new display filter 1999-07-07 22:52:57 +00:00
smb.h Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
snprintf-imp.h Squelch a number of "-Wall" errors by: 1998-10-13 07:03:37 +00:00
snprintf.c Changed two #include <>'s to #include "" 's, for stylistic reasons only. 1999-08-11 17:02:28 +00:00
snprintf.h Squelch a number of "-Wall" errors by: 1998-10-13 07:03:37 +00:00
strerror.c Add our own "strerror()", which we use on platforms that don't have it 1999-06-14 21:46:36 +00:00
strerror.h Add our own "strerror()", which we use on platforms that don't have it 1999-06-14 21:46:36 +00:00
summary.c Removed unnecessary #include "etypes.h" lines. 1999-08-24 17:26:16 +00:00
summary.h Since ethereal is now dependent on GTK+-1.2.x (because of proto_tree and 1999-07-13 03:08:06 +00:00
timestamp.h Added support for compiling on win32 with Visual C and 'nmake'. It compiles, 1999-07-13 02:53:26 +00:00
util.c The Single UNIX Specification doesn't say that "mkstemp()" creates the 1999-08-23 05:02:50 +00:00
util.h Make a "create_tempfile()" routine that constructs the template to be 1999-08-18 02:59:05 +00:00
xdlc.c No, 0xCC is SNRME. (I *told* you I hated reversing bit strings....) 1999-08-27 18:02:41 +00:00
xdlc.h Have "get_xdlc_control()" and "dissect_xdlc_control()" just return a 1999-08-23 23:24:36 +00:00

README

General Information
------- -----------

Ethereal is a network traffic analyzer, or "sniffer", for Unix and
Unix-like operating systems.  It uses GTK+, a graphical user interface
library, and libpcap, a packet capture and filtering library.

The official home of Ethereal is

    http://ethereal.zing.org

The latest distribution can be found in the subdirectory

    http://ethereal.zing.org/distribution

Interesting and exotic packet traces can be found at

    http://ethereal.zing.org/~gram/sample.html


Installation
------------

Ethereal is known to compile and run on the following systems:

  - Linux (2.0.x, 2.1.x, 2.2.x)
  - Solaris (2.5.1, 2.6)
  - FreeBSD (2.2.5, 2.2.6)
  - Sequent PTX v4.4.5  (Nick Williams <njw@sequent.com>)
  - Tru64 UNIX (formerly Digital UNIX) (3.2, 4.0)

It should run on other systems without too much trouble.

NOTE: the Makefile appears to depend on GNU "make"; it doesn't appear to
work with the "make" that comes with Solaris 7 nor the BSD "make".
Perl is also needed to create the man page.

If you decide to modify the yacc grammar or lex scanner, then
you need "flex" - it cannot be built with vanilla "lex" -
and either "bison" or the Berkeley "yacc". Your flex
version must be 2.5.1 or greater. Check this with 'flex -V'.

You must therefore install Perl, GNU "make", "flex", and either "bison" or
Berkeley "yacc" on systems that lack them.

Full installation instructions can be found in the INSTALL file.
         
See also the appropriate README.<OS> files for OS-specific installation
instructions.

Usage
-----          

In order to capture packets from the network, you need to be running
as root, or have access to the appropriate entry under /dev if your
system is so inclined (BSD-derived systems and Solaris typically fall
into this category.  Although it might be tempting to make the
Ethereal executable setuid root, please don't - alpha code is by nature
not very robust, and liable to contain security holes.

Please consult the man page for a description of each command-line
option and interface feature.


Multiple File Types
-------------------

The wiretap library is a packet-capture library currently under
development parallel to ethereal.  In the future it is hoped that
wiretap will have more features than libpcap, but wiretap is still in
its infancy. However, wiretap is used in ethereal for its ability
to read multiple file types. You can read the following file
formats, and create display filters for them as well:

libpcap, Sniffer (uncompresed), NetXray, Sniffer Pro, snoop,
Shomiti, LANalyzer, Network Monitor, iptrace 2.0 (AIX), and
RADCOM's WAN/LAN Analyzer

Although Ethereal can read AIX iptrace files, the documentation on
AIX's iptrace packet-trace command is sparse.  The 'iptrace' command
starts a daemon which you must kill in order to stop the trace. Through
experimentation it appears that sending a HUP signal to that iptrace
daemon causes a graceful shutdown and a complete packet is written
to the trace file. If a partial packet is saved at the end, Ethereal
will complain when reading that file, but you will be able to read all
other packets.  If this occurs, please let the Ethereal developers know
at ethereal-dev@zing.org, and be sure to send us a copy of that trace
file if it's small and contains non-sensitive data.


IPv6
----
If your operating system includes IPv6 support, ethereal will attempt to
use reverse name resolution capabilities when decoding IPv6 packets. If
you want to turn off name resolution while using ethereal, start ethereal
with the "-n" option. If you would like to compile ethereal without
support for IPv6 name resolution, use the "--disable-ipv6" option with
"./configure". If you compile ethereal without IPv6 name resolution,
you will still be able to decode IPv6 packets, but you'll only see IPv6
addresses, not host names.

The "Follow TCP Stream" feature only supports TCP over IPv4. Support for TCP
over IPv6 is planned.


SNMP
----
Ethereal can do some basic decoding of SNMP packets, but it relies on an
external SNMP library to do this. You can use either the UCD or the CMU
SNMP libraries. The configure script will automatically determine which
library you have on your system and will use it. If you have an SNMP
library but _do not_ want to have ethereal use it, you can run configure
with the "--disable-snmp" option. No SNMP support will be compiled into
ethereal with this option.


How to Report a Bug
-------------------
Ethereal is still under constant development, so it is possible that you will
encounter a bug while using it. Please report bugs to ethereal-dev@zing.org.
Be sure you tell us:

	1) Operating System and version
	2) Version of GTK+ (the command 'gtk-config --version' will tell you)
	3) The command you used to invoke Ethereal

If the bug is produced by a particular trace file, please be sure to send
a trace file along with your bug description. Please don't send a trace file
greather than 1 MB when compressed. If the trace file contains sensitive
information (e.g., passwords), then please do not send it.

If Ethereal died on you with a 'segmentation violation', you can help the
developers a lot if you have a debugger installed. A stack trace can be
obtained by using your debugger ('gdb' in this example), the ethereal binary,
and the resulting core file. Here's an example of how to use the gdb
command 'backtrace' to do so.

$ gdb ethereal core
(gdb) backtrace
..... prints the stack trace
(gdb) quit
$

Disclaimer
----------

There is no warranty, expressed or implied, associated with this product.
Use at your own risk.


Gerald Combs <gerald@zing.org>
Gilbert Ramirez <gram@xiexie.org>