[TOOL] WinPcap, the Free Packet Capture Architecture for Windows

From: support@securiteam.com
Date: 09/03/01


From: support@securiteam.com
To: list@securiteam.com
Subject: [TOOL] WinPcap, the Free Packet Capture Architecture for Windows
Message-Id: <20010903202730.70F29138C0@mail.der-keiler.de>
Date: Mon,  3 Sep 2001 22:27:30 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  WinPcap, the Free Packet Capture Architecture for Windows
------------------------------------------------------------------------

DETAILS

 <http://netgroup-serv.polito.it/winpcap/> WinPcap is an architecture for
packet capture and network analysis for the Win32 platforms. It includes a
kernel-level packet filter, a low-level dynamic link library (packet.dll),
and a high-level and system-independent library (wpcap.dll, based on
libpcap version 0.5).

The packet filter is a device driver that adds to Windows 95, Windows 98,
Windows ME, Windows NT, and Windows 2000 the ability to capture and send
raw data from a network card, with the possibility to filter and store in
a buffer the captured packets.

Packet.dll is an API that can be used to access directly the functions of
the packet driver, offering a programming interface independent from the
Microsoft OS.

Wpcap.dll exports a set of high-level capture primitives that are
compatible with libpcap, the famous UNIX capture library. These functions
allow capturing packets in a way independent from the underlying network
hardware and operating system.

ADDITIONAL INFORMATION

The Library can be downloaded from:
 <http://netgroup-serv.polito.it/winpcap/install/default.htm>
http://netgroup-serv.polito.it/winpcap/install/default.htm

The information has been provided by Loris Degioanni.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: TV Capture Cards - 10 - Then Freezes
    ... I have all the current drivers and the Windows Encoder ... continue to have the same problem - TV card video only runs ... With DScaler I am given an option to reset the capture card ...
    (microsoft.public.windowsxp.video)
  • IP protocol checksum errors
    ... Frame 3484 ... Time delta from previous packet: ... Capture Length: 254 bytes ... Fragment offset: 0 ...
    (comp.os.linux.embedded)
  • Re: Only some websites will open - Ubuntu
    ... I recently put together a new computer and installed Kubuntu ... However it MAY be to do with window sizes..in addition to the MTU - which is the MAX size of each data packet - there is a window size that is negotiated for a TCP connection..that specifies how much data can be sent without waiting for an ACK. ... I have no idea how t tune a Linux kernel for windows size tho. ...
    (comp.os.linux.misc)
  • Re: Movie Maker lost the abiliy to capture in DV-AVI from a camcor
    ... Uninstalled portions of the Yahoo Toolbar and Windows Live to fix other ... Did not test Movie Maker these changes. ... The trial system restore was in fact older than this capture. ... Is DV compatable with Firewire or 1394? ...
    (microsoft.public.windowsxp.moviemaker)
  • RE: Snort + (OpenBSD or Linux)
    ... Snort + (OpenBSD or Linux) ... >on the same packet. ... Regarding OpenBSD vs. Linux packet capture performance (this is a really old ...
    (Focus-IDS)