Re: [0/7] [PPP]: Fix shared/cloned/non-linear skb bugs (was: malformed captured packets)
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2007-09-19 11:51:53
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2007-09-19 11:51:53
On Tue, Sep 11, 2007 at 08:12:50PM +0200, Toralf Förster wrote:
I'm wondering why some UDP packets of the MS messenger protocol (with the usual text like "please click at www.we-destroy-your-computer.com") always have wrong check sums regardless whether sniffed at ppp0 or eth0 interface.
Maybe your wireshark is broken? I've tried wireshark and tcpdump here and the sums look fine.
and I'm wondering why it is still possible to capture such packets at eth0.
tcpdump happens before the packet goes into the IP stack which is whare iptables lives. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} [off-list ref] Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt