Wireshark-users: Re: [Wireshark-users] Wireshark for Beacon Sniffing

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Wed, 21 Jan 2009 17:40:33 -0800

On Jan 21, 2009, at 5:26 PM, Johne Cookcely wrote:

Hi! Wireshark just crashed "segmentation fault", so I can't tell for the long trace, unless its possible to extract from the file logged to disk...............

Unfortunately, it's not; libpcap capture format (Wireshark's native format) doesn't have any provision for storing packet-drop statistics.

Did Wireshark leave a core dump file? If so, can you run gdb with the Wireshark binary and the core file, and run the "backtrace" command to get a stack trace?

Does Wireshark crash if you try to read the file logged to disk?

I ran a short 4min 10000 packet trace and 0 packets "Lost" at the bottom of the screen.

"Lost" presumably meaning "Dropped", as that's the word Wireshark uses.