Ethereal-users: Re: [Ethereal-users] Ethereal and WLAN analysis

Note: This archive is from the project's previous web site, This list is no longer active.

From: Guy Harris <gharris@xxxxxxxxx>
Date: Mon, 2 Sep 2002 12:09:51 -0700
On Sun, Sep 01, 2002 at 09:57:05AM +0800, darren wrote:
> I know there are some programs like AirTraf and Kismet that does this,
> but I don't think they can read from capture files, just live traffic.


Wtapfile allows previously recorded dump files (from Ethereal,
PrismDump, PrismSnort, or Kismet itself) to be read and processed as a
live capture.  This can be to replay a sniff, or to process network,
cisco, and weak logfiles.

Wtapfile works like any other capture source, simply set the capture
interface to be the dumpfile, ie: `kismet -n --capture-type wtapfile
--capture-interface old.dump`"