I just rediscovered the Ethereal network protocol analyzer.  I was trying to track down a problem using the tcptrace proxy which is a nice simple little tool when it works.  I'm not quite sure what the problem was, but I was seeing different behavior when I was using the proxy than when I wasn't, so I went for the full blown driver level sniffing that Ethereal provides.  It's based on the work of the WinPCap organization.  I'll let you know why I was sniffing network packets in my next post.

  1. leppie says:

    Not the greatest UI, but how else would you fit all the info in? I love it 🙂

  2. JeffCurless says:

    The only problem I have with ethereal is the winpcap driver doesn’t work so well on dual processor systems.  Or atleast it didn’t used to.  The version I had would explicitly unload itself.  Or die trying.  Hope you like the color blue!

