How to handle the capture file. pcap which encapsulation type "linux cooked capture"

Apr 4, 2014 at 6:51 PM
How to handle the capture file. pcap which encapsulation type "linux cooked capture" ?
Coordinator
Apr 12, 2014 at 9:12 AM
Can you post an example .pcap file?
Apr 18, 2014 at 7:10 PM
Coordinator
Nov 15, 2014 at 4:37 PM
Fixed in Pcap.Net 1.0.0.
Dec 21, 2015 at 6:39 PM
Hi Brickner ,

I am having issue with this Linux cooked capture.. with such pcap files i am not able to read IPv4 Source and destination address correctly.

packet.IpV4.Source and packet.Ethernet.IpV4.Source give incorrect IP readings.......!

Please suggest how to deal with captures when Linux cooked capture is present.


Thanks
-Vivek
Dec 23, 2015 at 11:11 AM
You can strip the LLC layer
Coordinator
Feb 5, 2016 at 11:11 AM
Hi Vivek,

What version of Pcap.Net are you using?
A sample .pcap file would be helpful.
Also, the code you're trying to use to read it would also be helpful.
Please post a new question in the Pcap.Net Q&A group.

Boaz.
Mar 14, 2016 at 3:21 PM
I have raised a ticket title "Unable to read pcaket correctly form pcap.net if TCPdump captures on "any" port filter"

But i was not able to attach file there . I am attaching the file here .