# Anyone feel like testing my simple packet sniffer?

**URL:** https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189
**Category:** Miscellaneous and Personal Stuff I Must Share
**Created:** [March 29, 2004, 11:22pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189 "2004-03-29T23:22:38Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 1, 2004, 7:40pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/41 "2004-04-01T19:40:13Z")

</div>

Version that prompts user to choose interface:  
[http://users.adelphia.net/~tlaplaca/sps17.exe](http://users.adelphia.net/%7Etlaplaca/sps17.exe)

Wow, what a pain in the butt. It took me almost as long to get the new prompt dialog working as it took to make the entire first version that worked perfectly on my PC.

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 1, 2004, 8:17pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/42 "2004-04-01T20:17:04Z")

</div>

> [@Revtim](#):
>
> Version that prompts user to choose interface:  
> [http://users.adelphia.net/~tlaplaca/sps17.exe](http://users.adelphia.net/%7Etlaplaca/sps17.exe)
> 
> Wow, what a pain in the butt. It took me almost as long to get the new prompt dialog working as it took to make the entire first version that worked perfectly on my PC.

Good job. Interesting results.

The first time I loaded it, I selected my active connection and hit Start. One line jumped into the listbox, then the program stalled again as in the past, but crashed.

The second time, I loaded it, selected my connection, hit Start, and the listbox filled up with what looked like packets, but then the program closed itself.

Tried a third time, same as second time.

I’m not sure what happened on the first try, but in subsequent results, the packets appeared to be filling up, but then the program just died.

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 1, 2004, 8:20pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/43 "2004-04-01T20:20:21Z")

</div>

Tried again, got same results as the first try. This line appeared in the listbox:

1080850610:108802 (1434)

And it crashed with “TODO: \<File description\>” as the titlebar of the crash.

Ran it once more, it started filling up with packets again, and I managed to screen cap it right before it crashed (it crashes within 1-2 seconds). Screen cap is [here](http://www.people.virginia.edu/~dbh6j/sps.gif).

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 1, 2004, 9:30pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/44 "2004-04-01T21:30:30Z")

</div>

Likely, the problem is that it cannot handle those humongous packets you are getting. For some reason, your packets are WAY bigger than mine (now I have packey envy…)

A buddy who tried this version out for me told me it crashes when he makes a SQL request over the network, which would likely also result in very large packets.

And indeed I think I found the problem, please try #18

[http://users.adelphia.net/~tlaplaca/sps18.exe](http://users.adelphia.net/%7Etlaplaca/sps18.exe)

And as always, thank you for trying this for me.

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 1, 2004, 10:10pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/45 "2004-04-01T22:10:40Z")

</div>

> [@Revtim](#):
>
> Likely, the problem is that it cannot handle those humongous packets you are getting. For some reason, your packets are WAY bigger than mine (now I have packey envy…)
> 
> A buddy who tried this version out for me told me it crashes when he makes a SQL request over the network, which would likely also result in very large packets.
> 
> And indeed I think I found the problem, please try #18
> 
> [http://users.adelphia.net/~tlaplaca/sps18.exe](http://users.adelphia.net/%7Etlaplaca/sps18.exe)
> 
> And as always, thank you for trying this for me.

New error: 404 Not found 😃

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 1, 2004, 10:18pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/46 "2004-04-01T22:18:19Z")

</div>

Heh, for a second there I thought “How the @\*$& could my prog make a 404 error?”

Link should work now (I had misnamed it on the web space).

---

<div class="post-metadata">

### Author: ![Bambi\_Hassenpfeffer](https://avatars.discourse-cdn.com/v4/letter/b/bbe5ce/32.png) [@Bambi\_Hassenpfeffer](https://boards.straightdope.com/u/Bambi_Hassenpfeffer)
#### Post date: [April 1, 2004, 10:48pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/47 "2004-04-01T22:48:06Z")

</div>

Works a treat now, **Revtim**. I’ve been running it for about 10 minutes while I browse, and it’s displaying the packets just fine. Good work!

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 1, 2004, 11:01pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/48 "2004-04-01T23:01:59Z")

</div>

> [@Bambi Hassenpfeffer](#):
>
> Works a treat now, **Revtim**. I’ve been running it for about 10 minutes while I browse, and it’s displaying the packets just fine. Good work!

Thank you so much for taking the time to try it.

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 2, 2004, 12:39am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/49 "2004-04-02T00:39:41Z")

</div>

> [@Revtim](#):
>
> Thank you so much for taking the time to try it.

Hmm… well, now I’m using a wireless connection (laptop), and I selected it. No packets were displayed, but no lockup either. Tried the other two, also, but no packets. :-/

I’ll try it on a regular, wired ethernet card shortly.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 2, 2004, 2:51am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/50 "2004-04-02T02:51:40Z")

</div>

> [@caphis](#):
>
> Hmm… well, now I’m using a wireless connection (laptop), and I selected it. No packets were displayed, but no lockup either. Tried the other two, also, but no packets. :-/
> 
> I’ll try it on a regular, wired ethernet card shortly.

I’m really sorry if this is a dumb question, but did you force some network activity? Is it possible there simply wasn’t any packets?

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 2, 2004, 3:33am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/51 "2004-04-02T03:33:55Z")

</div>

> [@Revtim](#):
>
> I’m really sorry if this is a dumb question, but did you force some network activity? Is it possible there simply wasn’t any packets?

heh, yeah, forced network activity 😛

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 2, 2004, 8:00pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/52 "2004-04-02T20:00:28Z")

</div>

> [@caphis](#):
>
> heh, yeah, forced network activity 😛

I’m kinda stumped how to debug this wireless problem; in the meantime, have you tried it on the machine where it was crashing with the large packets? I strongly suspect it isn’t going to crash anymore, my buddy with the SQL reports it fixed in at least his situation.

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 2, 2004, 9:25pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/53 "2004-04-02T21:25:27Z")

</div>

> [@Revtim](#):
>
> I’m kinda stumped how to debug this wireless problem; in the meantime, have you tried it on the machine where it was crashing with the large packets? I strongly suspect it isn’t going to crash anymore, my buddy with the SQL reports it fixed in at least his situation.

I apologize… not yet, but I will tonight. 😃

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 2, 2004, 9:39pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/54 "2004-04-02T21:39:39Z")

</div>

No hurry man, thanks.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 3, 2004, 9:27pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/55 "2004-04-03T21:27:15Z")

</div>

OK, looks like WinPcap can’t detect every network device out there. From its FAQ at [http://winpcap.polito.it/misc/faq.htm](http://winpcap.polito.it/misc/faq.htm)

> [@](#):
>
> Q-16: Which network adapters are supported?
> 
> A: The NPF device driver was developed to work primarily with Ethernet adapters. Support for other MACs was added during the development, but Ethernet remains the most tested one. The main reason is that all our development stations have Ethernet adapters. However, the current situation is:
> 
> ```
> * Windows 95/98/ME: the packet driver works correctly on Ethernet networks. It works also on PPP WAN links, but with some limitations (for example it is not able to capture the LCP and NCP packets). FDDI, ARCNET, ATM and Token Ring should be supported, however we did not test them because we do not have the hardware, so do not expect them to work perfectly.
> * Windows NT4/2000: the packet driver works correctly on Ethernet networks. We were not able to make it work on PPP WAN links, because of binding problems on the NDISWAN adapter. As in Win9x, FDDI, ARCNET, ATM and Token Ring should be supported, but are not granted to work perfectly.
> * **Wireless adapters are not granted to work: some of them are not detected, other don't support promiscuous mode. In the best case, WinPcap is able to see an Ethernet emulation and not the real transiting packets**. The AirSnare website contains a page (http://home.comcast.net/~jay.deboer/airsnare/supported.htm) with a list of wireless adapters, specifying for each of them the ability to work with WinPcap.
> * VPN: some implementations are not detected because of their unclean NDIS intermediate driver structure.
> 
> ```

(Bolding mine)

So, it looks like the wireless problem is likely with WinpCap library.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 4, 2004, 4:28am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/56 "2004-04-04T04:28:07Z")

</div>

Made a new one, with just some minor UI changes.  
[http://users.adelphia.net/~tlaplaca/sps20.exe](http://users.adelphia.net/%7Etlaplaca/sps20.exe)

1. Pops an error window if the user tries to enter invalid/non-existant interface number
2. Added “End Program” button to interface-choosing dialog
3. Fixed bug where user could close the interface-choosing dialog and result with invalid ‘0’ interface “chosen”.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 5, 2004, 11:25pm UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/57 "2004-04-05T23:25:42Z")

</div>

> [@caphis](#):
>
> I apologize… not yet, but I will tonight. 😃

Had a chance yet?

---

<div class="post-metadata">

### Author: ![fruitbat](https://avatars.discourse-cdn.com/v4/letter/f/58f4c7/32.png) [@fruitbat](https://boards.straightdope.com/u/fruitbat)
#### Post date: [April 6, 2004, 12:06am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/58 "2004-04-06T00:06:44Z")

</div>

Ok I am now dying of curiousity. I am a Liberal Arts guy. I view computers as alien life forms with whom I have an uneasy symbiotic relationship. Please to explain what a ‘packet sniffer’ is and what it does. I opened this thread expecting it was a coy sexual reference. It now seems certain that I will have no satisfaction on that count. I figure I should get something out of this thread.

---

<div class="post-metadata">

### Author: ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)
#### Post date: [April 6, 2004, 12:20am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/59 "2004-04-06T00:20:47Z")

</div>

**fruitbat** , it’s a program that displays the raw data that passes through one’s network card.

It’s useful for diagnosing computer network problems (although ones that translate the data some are a lot more useful than my program.)

---

<div class="post-metadata">

### Author: ![caphis](https://avatars.discourse-cdn.com/v4/letter/c/e19adc/32.png) [@caphis](https://boards.straightdope.com/u/caphis)
#### Post date: [April 6, 2004, 3:54am UTC](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189/60 "2004-04-06T03:54:07Z")

</div>

eep- sorry, thought I had posted. Tried it on my other machine without wireless-- worked like a charm!

[Previous page](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189.md?page=2)

[Next page](https://boards.straightdope.com/t/anyone-feel-like-testing-my-simple-packet-sniffer/237189.md?page=4)
