<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">Hi everyone,<br>
<br>
It would appear that this post on technet is correct:<br>
<a class="moz-txt-link-freetext" href="http://social.technet.microsoft.com/Forums/en-US/4dc4d3d2-b47c-4297-b089-5f11e9c2ff8c/10041-and-winpcap-413-anyone-using-this">http://social.technet.microsoft.com/Forums/en-US/4dc4d3d2-b47c-4297-b089-5f11e9c2ff8c/10041-and-winpcap-413-anyone-using-this</a><br>
<br>
Windows 10 build 10074 does appear to be working again with
WinPcap 4.1.3.<br>
<br>
Chris.<br>
<br>
On 29/03/2015 13:58, Daniel Miller wrote:<br>
</div>
<blockquote
cite="mid:CABmvJnMmvHJOGLH73YWwrbkwEcm43gC4LNN4_dKHMXfUdTf2qw@mail.gmail.com"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<div dir="ltr"><br>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Sun, Mar 29, 2015 at 5:24 AM,
Pascal Quantin <span dir="ltr"><<a
moz-do-not-send="true"
href="mailto:pascal.quantin@gmail.com" target="_blank">pascal.quantin@gmail.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px
0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div class="gmail_extra">
<div class="gmail_quote">
<div>
<div>2015-03-25 16:45 GMT+01:00 Pascal Quantin <span
dir="ltr"><<a moz-do-not-send="true"
href="mailto:pascal.quantin@gmail.com"
target="_blank">pascal.quantin@gmail.com</a>></span>:<br>
<blockquote class="gmail_quote"
style="margin:0px 0px 0px
0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div>
<div>
<div>Hi all,<br>
<br>
</div>
as reported on this blog post: <a
moz-do-not-send="true"
href="http://netscantools.blogspot.fr/2015/03/winpcap-and-wireshark-problems-on.html"
target="_blank">http://netscantools.blogspot.fr/2015/03/winpcap-and-wireshark-problems-on.html</a>,
network interfaces are no more showing
up on the latest Windows 10 build (I see
the same thing on my virtual machine).<br>
</div>
I could not find any clear information
yet, but I fear it could imply that
Microsoft is gonna drop the NDIS 5
backward compatibility mode sooner or
later (which should be expected at some
point as NDIS 6 was introduced in Vista).
Given the number of products / projects
that rely on WinPcap (Wireshark being one
of them), having it not working anymore in
the latest Microsoft OS would be a drama.<br>
</div>
<div>I know that the project is more or less
stalling since a few years. An "emergency"
fix was done for Windows 8 support, but I
have no idea whether having it working on
Windows 10 requires a small fix or a full
rewrite.<br>
</div>
<div>Could one of the developer kindly have
a look and provide some info regarding the
Windows 10 compatibility / WinPCAP future?<br>
</div>
</div>
</blockquote>
<div><br>
</div>
</div>
</div>
<div>Hi all,<br>
<br>
</div>
<div>as indicated by Jakub Zawadzki, there was a
Nmap GSoc 2013 project porting Winpcap to NDIS 6,
with the source code found here: <span> <a
moz-do-not-send="true"
href="https://svn.nmap.org/nmap-exp/yang/NPcap-LWF/installer/winpcap-nmap-4.1.3-NDIS6-1.2.0.exe"
target="_blank">https://svn.nmap.org/nmap-exp/yang/NPcap-LWF</a><br>
</span></div>
<div><span>After a quick test, I can confirm that:<br>
</span></div>
<div><span>- interfaces are now seen and can be
selected for capture<br>
</span>
<div>- ethernet frames containing TCP packets are
seen with a size of 2048 bytes (while I have a
MTU set to 1500) and the extra data is seen as
ethernet trailer of 570 bytes + a FCS of 4 bytes<br>
</div>
- DNS queries are truncated (only the first 8
bytes of UDP datagram are captured)<br>
</div>
<div>So this is not yet usable but seems to be a
good starting point.<br>
<a moz-do-not-send="true"
href="http://seclists.org/nmap-dev/2013/q4/108"
target="_blank">http://seclists.org/nmap-dev/2013/q4/108</a>
suggests that the code was shared with WinPcap
development team (or at least this was the
intention). Did this ever happened?<br>
<br>
</div>
<div>Best regards,<br>
</div>
<div>Pascal.<br>
</div>
</div>
</div>
</div>
<br>
</blockquote>
<div> </div>
</div>
<div>Pascal,<br>
<br>
</div>
<div>I haven't seen a reply from a WinPcap developer on this
list for a long time, but I can confirm that Nmap is looking
to revive the Npcap project. It's one of our "official
ideas" for GSOC 2015, and we have several applicants for the
position, including the student who did the original work.
If you want to stay engaged with that effort, continue to
watch the <a moz-do-not-send="true"
href="mailto:dev@nmap.org" target="_blank">dev@nmap.org</a>
mailing list over the summer; I'm sure we would appreciate
feedback as the project progresses.<br>
<br>
</div>
Dan </div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
Winpcap-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Winpcap-users@winpcap.org">Winpcap-users@winpcap.org</a>
<a class="moz-txt-link-freetext" href="https://www.winpcap.org/mailman/listinfo/winpcap-users">https://www.winpcap.org/mailman/listinfo/winpcap-users</a>
</pre>
</blockquote>
<br>
<br>
<div class="moz-signature">-- <br>
<p style="color: #000000"><strong>Chris Thomas</strong><br>
Chief Technical Officer - Idappcom Ltd</p>
<h3 style="color: #338833;"><strong>Watch the video series for our
latest software <a
href="https://www.youtube.com/channel/UCzel4u3CGsQmgncCtfKq4lA">"The
Easy Rules Manager (Snort)"</a></strong></h3>
<p>Office: +44(0)203-355-6804 x 4201 - Fax: +44(0)203-393-9950<br>
Web: <strong><a href="http://www.idappcom.com">www.idappcom.com</a></strong>
and <strong><a href="http://www.ipssecurityrules.co.uk">www.ipssecurityrules.co.uk</a></strong><br>
Mail: Idappcom Ltd, 6 Rural Enterprise Centre, Eco Park Road,
Ludlow, Shropshire, SY8 1FF, UK.</p>
<img moz-do-not-send="false"
src="cid:part10.04090903.00070004@idappcom.com" alt="idappcom
ltd">
<h5 style="color: #244061">Registered in England No. 06829932. 11
Welbeck Street, London, W1G 9XZ</h5>
<h5>IMPORTANT: The information contained in this e-mail and
attachment (if any) is intended for the person to whom it is
addressed and may contain confidential and/or privileged
information. The contents of this message may contain personal
views which are not the views of Idappcom Ltd, unless
specifically stated. You should not copy, retain, forward or
disclose its contents to anyone else, or take any action based
upon it, if it is not addressed to you personally. If you have
received this e-mail in error please contact the sender
immediately.</h5>
<h5 style="color: green">Please don't print this e-mail unless you
really need to.</h5>
</div>
</body>
</html>