Hi guys
I experienced this problems some days ago using tcpdump and tethereal.
I made a capture with tcpdump in order to get OSPF packets. My filter
was ip[21]==89. I saved my data into a pcap file, but when I opened it
with ethereal I found many packets marked [Short frame], and effectively
they where truncated. I made the same capture with tethereal (same
options) and I got a different result: the packets where captured
correctly, at full lenght.
These are my versions:
Red Hat Linux release 8.0 (Psyche)
tcpdump-3.6.3-17.8.0.3
ethereal-0.9.13-1.80.1
libpcap-0.6.2-16
Any idea?
--
Dario Lombardo
Centro Sicurezza Be-Secure
Telecom Italia LAB
====================================================================
CONFIDENTIALITY NOTICE
This message and its attachments are addressed solely to the persons
above and may contain confidential information. If you have received
the message in error, be informed that any use of the content hereof
is prohibited. Please return it immediately to the sender and delete
the message. Should you have any questions, please contact us by
replying to MailAdmin@xxxxxxxxx. Thank you
====================================================================