pcap struct pcap_pkthdr len vs caplen

前端 未结 3 2075
慢半拍i
慢半拍i 2021-02-01 02:42

We\'re sniffing packets using libpcap on linux The header we get on each packet looks like:

struct pcap_pkthdr {
        struct timeval ts;      /* time stamp */         


        
3条回答
  •  暗喜
    暗喜 (楼主)
    2021-02-01 03:22

    Your understanding is correct, at least based on the pcap man page.

    caplen is the amount of data available to you in the capture. len was the actual length of the packet.

    I'm not aware of any cases that would give you a caplen > len. I usually seem them being equal as my snaplen is sufficiently high.

提交回复
热议问题