Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Sniffer .enc file format

Posted on 2004-08-04
4
Medium Priority
?
1,645 Views
Last Modified: 2008-02-01
Hi all,

I've been given the task of writing a sniffer-like tool that, among other things, saves files in the .enc etherpeek compatible file format.  Firstly though, I need to determine whether the customised information I'll be grabbing off the network has everything I require to actually produce a proper .enc file before I go and code it.  I found this link: http://www.networkuptime.com/tips/file_formats/ which says "original Ethernet trace file format is detailed in the Sniffer documentation" but the link to that file is dead.  Does anyone know where I can find this info or at least give a quick breakdown of the file structure?  My Google searches so far have been less than fruitful :-(

Thanks,
daecks
0
Comment
Question by:daecks
  • 3
4 Comments
 
LVL 1

Expert Comment

by:tropsmr2
ID: 11719928
Possibly you might take a look at the Ethereal source code.  It is a free sniffer that can write outputs in many formats, including .enc.

http://www.ethereal.com/development.html

PS:  Why write the program when you could employ Ethereal for nothing?
0
 
LVL 1

Accepted Solution

by:
tropsmr2 earned 375 total points
ID: 11720019
0
 

Author Comment

by:daecks
ID: 11728308
Thanks for your help tropsmr2

Also, found a working link to the document in the source code: http://www.nai.com/common/media/sniffer/support/sdos/operation.pdf

cheers,
daecks
0
 
LVL 1

Expert Comment

by:tropsmr2
ID: 11729147
Glad to hear that you're on your way!  Cheers and best of luck with your project...troy
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question