

And to say that Wireshark is Ethereal, without permission by NIS, is aginst the law. Untill NIS has to remove the program, then they own Ethereal, and the name, and it's two completely diffrent projects. Wireshark is a new project using the same code base of Ethereal, sorta like Firefox vs. It could be that they will countune development of Ethereal. Until that one acknowledges wireshark as the NEW ethereal, this is propaganda. Guy Harris 19:35, 23 June 2006 (UTC) Reply But Ethereal, the name, isn't his now.

Gerald didn't take "some people" with him - we all went. Untill says it is now wireshark, then wireshark is a seperate program, broken off of the first.- Ozzy 98 18:40, 23 June 2006 (UTC) Reply Every one of the core Ethereal developers (the ones with Subversion commit privileges to the repository) is now a Wireshark developer. They are two seperate objects, and how one transforms into the other hasn't been shown. Wireshark is not Ethereal, so please don't change Ethereal into wireshark. It may very well be that ethereal keeps going, and this project flops, just because of the name and backing. So, this is a fork in the application development, unless the people at ethereal agree with it. And ethereal is still listed, and has not made not of this. While the MAIN dev left, and took some people with him, he doens't own ethereal. I'm not sure if those should be changed because Ethereal not Wireshark was included? Jdm64 18:43, 9 June 2006 (UTC) Reply I've replaced the screenshot and caption of the screenshot.- T3h 07:48, 10 June 2006 (UTC) Reply I wouldn't change anythign right now. There still are some links, mostly ones that talk about Ethereal being included with an OS (i.e. Jdm64 15:12, 9 June 2006 (UTC) Reply Ok, I've changed most links to now point to Wireshark instead of Ethereal. This article should be moved and all links updated. $ grep "500 Error" *.Ethereal has chaged it's name to WireShark ( explained here). It is now easy to use grep, wc and sort on data. POST /ReportingWebService/ReportingWebService.asmx HTTP/1.1 With a sample downloaded at, the result is : $ ls -l *.http xmlstartlet, command line tool to work with XML ( ).With the -w trace.pcap parameter, raw captured data are written to the trace.pcap file. The option -s 0 enables capture of the whole packets and not only the first 64 bytes of each. This bash tip can be useful when trying to extract all HTTP requests from PCAP generated traces.įirst, use this command to generate the pcap file : # tcpdump -s 0 -w trace.pcap
