[Winpcap-users] RE: [tcpdump-workers] Support for win32 named pipes

Steighton_Haley at McAfee.com Steighton_Haley at McAfee.com
Wed Jun 29 17:39:57 GMT 2005


> 
> Can you please give additional explanation to your message?
> At present winpcap sniffs named pipes communication from 
> MSSQL server client on another computer to a MSSQL server.  
> However, it does not catch local named pipes communications.  

The reason for this is the same as the reason that WinPcap doesn't
capture any type of network packets sent to the loopback interface...
The net response is that WinPcap is an NDIS layer driver, and Windows
does not propagate packets to the localhost interface to the NDIS layer.

> 
> What your development adds to these options?

Unfortunately, there is nothing that can be done to capture these
packets with the current WinPcap architecture.

SLH.




More information about the Winpcap-users mailing list