Ethereal

Re: [Ethereal-users] tcpdump and libpcap
Google
 
Web Ethereal.com

Home | Introduction | Documentation | Lists | FAQ | Development | Wiki | Bugs

Ethereal-users: June 2001


> I'd like to know the difference between tcpdump and libpcap.

libpcap is a library that uses the underlying OS's packet capture
mechanism (or, in the case of WinPcap and Windows, the packet capture
mechanism supplied with WinPcap, as Windows doesn't come with a packet
capture mechanism) to supply raw network packets to an application, and
that also includes code to save captures to a file and read those files.

tcpdump is a packet-capture-and-analysis application built atop libpcap.

> Also I would like to know if there is a way to use the packets to
> reconstruct the original contents.  In this case I'm not using ethereal but
> I'm relying on tcpdump (or libpcap) only.

The original contents of what?



Powered by MHonArc 2.6.10