Wireshark-bugs: [Wireshark-bugs] [Bug 11699] New: Remote Interface settings shouldn't use UDP as

Date: Thu, 12 Nov 2015 12:11:02 +0000
Bug ID 11699
Summary Remote Interface settings shouldn't use UDP as default for data transfer
Product Wireshark
Version unspecified
Hardware x86
OS Windows NT
Status UNCONFIRMED
Severity Major
Priority Low
Component Qt UI
Assignee [email protected]
Reporter [email protected]

Created attachment 13999 [details]
Remote settings with UDP as default

Build Information:
Version 2.0.0rc3 (v2.0.0rc3-0-g841d5e1 from master-2.0)

Copyright 1998-2015 Gerald Combs <[email protected]> and contributors.
License GPLv2+: GNU GPL version 2 or later
<http://www.gnu.org/licenses/old-licenses/gpl-2.0.html>
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with Qt 5.3.2, with WinPcap (4_1_3), with libz 1.2.8, with
GLib 2.42.0, with SMI 0.4.8, with c-ares 1.9.1, with Lua 5.2, with GnuTLS
3.2.15, with Gcrypt 1.6.2, with MIT Kerberos, with GeoIP, with QtMultimedia,
with AirPcap.

Running on 64-bit Windows 10, build 10240, with locale C, with WinPcap version
4.1.3 (packet.dll version 4.1.0.2980), based on libpcap version 1.0 branch
1_0_rel0b (20091008), with GnuTLS 3.2.15, with Gcrypt 1.6.2, without AirPcap.
AMD Phenom(tm) II X4 905e Processor, with 7934MB of physical memory.


Built using Microsoft Visual C++ 12.0 build 31101

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
The GTK build doesn't use UDP in the remote interface options as default for
data transfer since version 1.4.x

I think, the QT build should also uncheck the flag as default, as the UDP
option is handled like an active mode in WinPCAP, which may force users to
disable/configure their firewall.
Explenation: UDP mode opens a UDP socket on the machine with Wireshark which
waits for a socket connect, which can be seen in the WinPCAP sources
(pcap-remote.c):

if ( (active) || (fp->rmt_flags & PCAP_OPENFLAG_DATATX_UDP) )


You are receiving this mail because:
  • You are watching all bug changes.