Wireshark mailing list archives

Re: Fake MAC addresses in text2pcap and "Import from hex dump"


From: Anders Broman <anders.broman () ericsson com>
Date: Tue, 12 Apr 2016 08:47:23 +0000



-----Original Message-----
From: wireshark-dev-bounces () wireshark org [mailto:wireshark-dev-bounces () wireshark org] On Behalf Of Guy Harris
Sent: den 12 april 2016 02:04
To: Developer support list for Wireshark
Subject: [Wireshark-dev] Fake MAC addresses in text2pcap and "Import from hex dump"

When synthesizing an Ethernet header, text2pcap uses 0a:02:02:02:02:02 as the destination address and 0a:01:01:01:01:01 
as the source address, while "Import from hex dump" uses 20:52:45:43:56:00 as the destination and 20:53:45:4E:44:00 as 
the source.

Is there some reason why they're different?

If not, which of them *should* both be using?
Even if  R E C V and S E N D is clever I think I prefer the other one which makes it clearer that it's a fake MAC.

Regards
Anders
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: