Wireshark-dev: [Wireshark-dev] text2pcap once again
Date: Tue, 9 Jan 2007 18:22:15 +0530
Hi Guy Harris ,
 
    armed with what you've learned from that book about the format of Ethernet headers and IP headers,
     look at the first 14 bytes of data in the packet (you'll now know how that produces the display
 
Thanks for the above suggestion especially the book.
But I'm already aware of the IP packet format , but some how I'm not able to map the values to the different header fields .
 
000000 00 e0 1e a7 05 6f 00 10
000008 5a a0 b9 12 08 00 46 00
000010 03 68 00 00 00 00 0a 2e
000018 ee 33 0f 19 08 7f 0f 19
000020 03 80 94 04 00 00 10 01
000028 16 a2 0a 00 03 50 00 0c
000030 01 01 0f 19 03 80 11 01
 
Please correct me if I'm wrong , but as per my understanding , if I have a file "test" with the above values as content then the below command will generate an IP packet using these values and add some dummy ethernet header values to it.
Command :    text2pcap test test123.pcap 
 
So could you please tell me which values from above would correspond to IP header portions like : 
1) version
2)IHL
3)TOS
4)Total length
5)Identification ......... etc .
 
Thanks once again for your response , hope to get some further inputs again .
Note : This is related to the mail titled "text2pcap help needed " .
 
Regards ,
Vikash
 

The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments.

WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email.

www.wipro.com