Hi All,
> Does anyone know of a utility, similar to 'text2pcap' but for
> Windows, for translating packet trace hex dumps into a file
> that is readable by Ethereal.
text2pcap.exe should be in your ethereal install directory. It works
perfectly for Ethernet text. However I cannot get Token ring text to be
reimported.
>From net/bpf.h:
#define DLT_EN10MB 1 /* Ethernet (10Mb) */
#define DLT_PRONET 4 /* Proteon ProNET Token Ring */
So I assume that text2pcap -l 4 should import token ring.
D:>tethereal -x -r trace.dmp | perl -ne "print if /^[0-9A-Fa-f]\d{4} /" >
trace.txt
D:>text2pcap -l 4 trace.txt trace2.dmp
Input from: trace.txt
Output to: trace2.dmp
Wrote packet of 62 bytes
Wrote packet of 160 bytes
<snip>
Read 23 potential packets, wrote 23 packets
D:\>tethereal -r trace2.dmp
Message: pcap: network type 4 unknown or unsupported
tethereal: The file "trace2.dmp" is a capture for a network type that
Tethereal doesn't support.
Does anyone have an ideas what's going here?
Alistair
-----------------------------------------------------------------------
Registered Office:
Marks & Spencer p.l.c
Michael House, Baker Street,
London, W1U 8EP
Registered No. 214436 in England and Wales.
Telephone (020) 7935 4422
Facsimile (020) 7487 2670
www.marksandspencer.com
Please note that electronic mail may be monitored.
This e-mail is confidential. If you received it by mistake, please let us know and then delete it from your system; you should not copy, disclose, or distribute its contents to anyone nor act in reliance on this e-mail, as this is prohibited and may be unlawful.
The registered office of Marks and Spencer Financial Services PLC, Marks and Spencer Unit Trust Management Limited, Marks and Spencer Life Assurance Limited and Marks and Spencer Savings and Investments Limited is Kings Meadow, Chester, CH99 9FB.