Re: end of tcp stream .
- From: "Alexander Nickolov" <agnickolov@xxxxxxxx>
- Date: Thu, 28 Jul 2005 17:33:39 -0700
Getting a TCP FIN or RST flag is the end of the connection.
Not sure if that's what you wanted, as you probably don't want
to buffer the entire TCP conversation before processing - it
may be in the order of megabytes or even gigabytes...
--
=====================================
Alexander Nickolov
Microsoft MVP [VC], MCSD
email: agnickolov@xxxxxxxx
MVP VC FAQ: http://www.mvps.org/vcfaq
=====================================
"Sharon" <Sharon669@xxxxxxxxxxx> wrote in message
news:OnOv7h2kFHA.3828@xxxxxxxxxxxxxxxxxxxxxxx
> Hi all
>
> I'm a java/bv programmer sorry for my lack of Winsock knowledge (and lack
> of
> good English .)
>
>
>
> I had this task to implement a simple sniffer (C code using Winsock )
>
> searching the internet i found relatively simple code , and changed it
> successfully according to my needs .
>
>
>
> My problem is like that:
>
>
>
> I am monitoring data sent over the TCP protocol,
>
> The broadcasting station transmits different sizes of data, the problem I
> encountered was when sending 6000 bytes of data.
>
>
>
> This data is fragmented into 4 frames 1514 size each, between them I get
> ACK frames
>
> So I tried to count on the PUSH flag of TCP , but on the second frame -
> the
> PUSH flag is 1
>
>
>
> Professional sniffer shows something like :
>
>
>
> 1# frame 1514 PUSH = 0
>
> 2# frame 1514 PUSH = 1
>
> 3# frame 60 ACK
>
> 4# frame 60 ACK
>
> 5# frame 1514 PUSH = 0
>
> 6# frame 1514 PUSH = 1
>
> ..
>
>
>
>
>
> What I'm trying to understand is how do I know when is the end of the TCP
> data
>
> How do I know when to stop extracting data from the TCP frames and send
> the
> data to my host application (one level up)
>
>
>
> Thank you very much
>
> I will appreciate any help !
>
> Sharon
>
.
- Follow-Ups:
- Re: end of tcp stream .
- From: Eugene Gershnik
- Re: end of tcp stream .
- References:
- end of tcp stream .
- From: Sharon
- end of tcp stream .
- Prev by Date: Winsock LSP capturing DNS queries
- Next by Date: Re: Winsock LSP capturing DNS queries
- Previous by thread: Re: end of tcp stream .
- Next by thread: Re: end of tcp stream .
- Index(es):
Relevant Pages
|