LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > Programming
User Name
Password
Programming This forum is for all programming questions.
The question does not have to be directly related to Linux and any language is fair game.

Notices


Reply
  Search this Thread
Old 12-03-2003, 01:06 PM   #1
ski_nm
LQ Newbie
 
Registered: Nov 2003
Posts: 2

Rep: Reputation: 0
need help on compare tool


i am relatively new to prgramming and need to come up with a tool (preferably in C) that will compare to tcpdump files for similarities in the tcp ip and ethernet sections.

i have two output files that should be pretty close but want to ensure they are or note the differences in an output format that is understandable. I am just beginning and any help is appreciated, I have no code yet to post but hopefully will soon

thanks

ski
 
Old 12-03-2003, 01:50 PM   #2
MartinN
Member
 
Registered: Nov 2003
Location: Ronneby, Sweden
Posts: 555

Rep: Reputation: 30
If your goal is to compare files, then 'diff' could be the right thing for you (man diff). But if the goal is some cool programming, then I can only say: --Happy hacking!

Regards
Martin
 
Old 12-03-2003, 04:19 PM   #3
Hko
Senior Member
 
Registered: Aug 2002
Location: Groningen, The Netherlands
Distribution: Debian
Posts: 2,536

Rep: Reputation: 111Reputation: 111
In this case 'diff' doesn't sound very useful to me, thinking of tcpdump files.

Ski: Maybe you could have a look at the pcap library. tcpdump and similar programs use it to read and write their (binary) packet capture files.
See:

"man 3 pcap" (install libpcap-dev package if the man page isn't there) or the webbed man-page

and/or the pcap tutorial
 
Old 12-04-2003, 12:59 PM   #4
ski_nm
LQ Newbie
 
Registered: Nov 2003
Posts: 2

Original Poster
Rep: Reputation: 0
thnaks for the replies. Yeah, diff wont work to well with the hex/binary files. I am trying to extract the IP, TCP and payload portions from the packet and compare these entries among two files. I have looked through the pcap library and see a couple of functions to read in the packets, but I am still not sure how to parse the ip, tcp, etc headers out of them
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
compare two folders bluenectar Linux - Newbie 10 08-04-2005 11:23 PM
Beyond Compare / WinDiff riluve Linux - Newbie 6 01-26-2005 08:05 AM
how to compare decimals linuxboy69 Linux - Software 2 08-16-2004 02:43 PM
URLSCAN tool MS = Linux tool ? OB1 Linux - Security 3 10-05-2002 12:58 AM
Is there any *FILE CONTENT COMPARE* tool in Linux? yuzuohong Linux - General 3 07-14-2002 06:11 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > Programming

All times are GMT -5. The time now is 01:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration