Ethereal-dev: Re: [Ethereal-dev] Network Associates .ENC capture files

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <guy@xxxxxxxxxx>
Date: Wed, 9 Jan 2002 11:02:21 -0800 (PST)
> I am trying to decypher the format of "Network Associates .ENC
> (DOS-based)" capture files.

That's the format supported by "wiretap/ngsniffer.c".

They have documented part of the format in various Sniffer manuals;
however, they haven't documented the format of all of the records.  The
stuff we *do* know (either from the manuals, or from reverse
engineering) is in that source file.