Hi,
But then why configure comes with option --disable-dumpcap ?
Oh, Ok, because if some one wants only to dissect packets from a captured files. right ?
Moheed
On Thu, May 29, 2008 at 11:06 PM, Guy Harris <
guy@xxxxxxxxxxxx> wrote:
Moheed Moheed Ahmad wrote:
> Is it must for 1.0.0 to have dumpcap built in order to tshark work?
Yes, if you want to capture network traffic; both Wireshark and TShark
run dumpcap to do the capturing (so the process doing the capturing,
which might have to run with special privileges, doesn't do any
dissection, so a bug in a dissector won't cause problems in a privileged
process).
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users
--
Moheed Moheed Ahmad