tcpdump mailing list archives

question regarding pcap


From: "subramoni padmanabhan" <smoni77 () hotmail com>
Date: Mon, 23 Dec 2002 01:12:36 -0500

hi,

I have a question. I have to capture all UDP packets belonging to a particular group. The group iD is a 64-bit quantity which starts at the first byte of the payload(right after the udp header). How do I write a pcap filter expression to capture all such packets? As far as I know, we can only compare one byte. In my case, I need to compare 8 bytes to a particular value. any ideas on how this can be accomplished? Thanks.



Subramoni Padmanabhan
G-126, 700 woodland avenue
Lexington, Kentucky 40508
Phone : 859 323 9405




_________________________________________________________________
The new MSN 8: smart spam protection and 3 months FREE*. http://join.msn.com/?page=features/junkmail&xAPID=42&PS=47575&PI=7324&DI=7474&SU= http://www.hotmail.msn.com/cgi-bin/getmsg&HL=1216hotmailtaglines_smartspamprotection_3mf

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:tcpdump-workers-request () tcpdump org?body=unsubscribe


Current thread: