Solved

WinDump file output is garbled...

Posted on 2002-04-21
8
971 Views
Last Modified: 2008-01-09
When I run windump and output to the dos window everything
works fine, but when I output to a file, most of the
information is garbled. For instance, the URLs contain
an empty square character where there should be a period.
Looks like this: www(square)somedomain(square)com. This
empty square character appears quite frequently in the file output...I tried using different file formats..but no luck. I guess I can read the urls, but pretty much all
the other info is destroyed in the output.
Does anyone know how to fix this??



Neil D
0
Comment
Question by:cMan
8 Comments
 
LVL 63

Expert Comment

by:SysExpert
Comment Utility
The problem is in the editor you are using to view the files.
Either find one that can handle or ignore Tabs, and other garbage characters - or use

find- replace to remove them.

I hope this helps !
0
 
LVL 63

Expert Comment

by:SysExpert
Comment Utility
For a good Free editor see


   http://www.notetab.com/ (main site)
Get NoteTab Light.

I hope this helps !

0
 

Author Comment

by:cMan
Comment Utility
Using NoteTab light the file doesnt even open at all, except for a few garbled characters at the beginning. Maybe I should have mentioned at the beginning that the editors I tried using were notepad, wordpad, ms word 2000, and of course NoteTab light...Could I be doing something
myself to corrupt the file...I use the following command
to start windump: "windump.exe -w c:\myfile.txt"...After
the program runs for a few minutes I do "Control + Break"
to terminate it, and then I open the file to see the output....you know the rest.

Neil D
0
 
LVL 63

Expert Comment

by:SysExpert
Comment Utility
This may have been designed for a UNIX machine, and noone bothered to change the formatting options of the output.

Try a Windows version of vi or similar.

0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:cMan
Comment Utility
vi???????
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Have you tried using Wordpad?
0
 
LVL 4

Accepted Solution

by:
newmang earned 250 total points
Comment Utility
cMan

How are you instructing windump to put the output to a file?

If you are using the "windump -w mycapture" command to output the data to mycapture then you will not be able to load the file to an editor and read it. This data is actually a binary capture file which is meant to be re-processed by windump using the -r mycapture option at a later time - in other words it allows you to capture raw data now then reprocess it using various filters later on.

I suspect that what you want to do is to capture what would normally come out on the screen into a file. If this is the case then you need to use redirection as follows:

windump > this_should_be_readable.txt

and this file will be readable in any editor.

Cheers - Gavin
0
 

Author Comment

by:cMan
Comment Utility
Gavin!!! Thank you so much!!
Now I can output the data to file just as it appears in the console window...I understand perfectly now..thank you.
I also like the idea of leaving the file as binary so I can use windump to extract just the data I want. I'll save that one for another time though.

Neil D
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Link Aggregation 2 31
Nic to NIC 5 44
network timeout on mapped drive 3 25
Not able to route between subnets 8 30
Lets look at the default installation and configuration of FreeProxy 4.10 REQUIREMENTS 1. FreeProxy 4.10 Application - Can be downloaded here (http://www.handcraftedsoftware.org/index.php?page=download) 2. Ensure that you disable the windows fi…
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now