<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Open Source Network Monitor Parsers</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx</link><description>With the release of Network Monitor 3.2 we plan to do all of our parser development as an open source project on http://www.codeplex.com/NMParsers . We will be releasing parser packages for Microsoft Protocols on a regular schedule. All parser issues</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Network Monitor 3.2 has arrived!</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3125225</link><pubDate>Wed, 17 Sep 2008 17:32:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3125225</guid><dc:creator>Network Monitor</dc:creator><description>&lt;p&gt;I’m so excited about this release I had to commandeer Paul’s blog for the day and write about it. My&lt;/p&gt;
</description></item><item><title>Microsoft Network Monitor 3.2 verfuegbar</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3125258</link><pubDate>Wed, 17 Sep 2008 18:38:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3125258</guid><dc:creator>Forefront &amp; Security Blogs</dc:creator><description>&lt;p&gt;Wie bereits angek&amp;#252;ndigt, befand sich die aktuelle Version des Microsoft Netzwerkmonitor seit Juni in&lt;/p&gt;
</description></item><item><title>E’ arrivato Network Monitor 3.2</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3126764</link><pubDate>Mon, 22 Sep 2008 15:06:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126764</guid><dc:creator>ZenIT Blog</dc:creator><description>&lt;p&gt;E’ disponibilie (scaricabile da qui ) la nuova versione di Network Monitor . Il team di sviluppo ha lavorato&lt;/p&gt;
</description></item><item><title>E’ arrivato Network Monitor 3.2</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3126766</link><pubDate>Mon, 22 Sep 2008 15:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126766</guid><dc:creator>Blog Team TechNet Italia</dc:creator><description>&lt;p&gt;E’ disponibilie (scaricabile da qui ) la nuova versione di Network Monitor . Il team di sviluppo ha lavorato&lt;/p&gt;
</description></item><item><title>re: Open Source Network Monitor Parsers</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3145087</link><pubDate>Fri, 31 Oct 2008 09:57:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145087</guid><dc:creator>Ponyo</dc:creator><description>&lt;p&gt;I tried to parse NAP DHCP Enforcement SoH packet between Vista and Server 2008.&lt;/p&gt;
&lt;p&gt;The first 255 bytes of Vendor Specific Information are parsed correctly,&lt;/p&gt;
&lt;p&gt;however, the rest of data are not parsed.&lt;/p&gt;
&lt;p&gt;Is this a bug of Network Monitor SoH Parser ?&lt;/p&gt;
&lt;p&gt;If so, when will it be fixed ?&lt;/p&gt;
</description></item><item><title>re: Open Source Network Monitor Parsers</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3145243</link><pubDate>Fri, 31 Oct 2008 16:40:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145243</guid><dc:creator>PaulELong</dc:creator><description>&lt;p&gt;I can't tell from your description, but if you can send me the capture(use the email link from this blog) OR just send me all the HEX data in the packet and I can reconstruct it.&lt;/p&gt;
&lt;p&gt;There is a limitation with Information that is fragmented into multiple packets with in the same frame. &amp;nbsp;This is something we'll need to support with the engine, we call this inner frame fragmentation. &amp;nbsp;If this is the issue, there will be a limitation to parse it.&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
</description></item><item><title>re: Open Source Network Monitor Parsers</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3146859</link><pubDate>Tue, 04 Nov 2008 05:25:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3146859</guid><dc:creator>Ponyo</dc:creator><description>&lt;p&gt;Hi Paul,&lt;/p&gt;
&lt;p&gt;Thank you for your response.&lt;/p&gt;
&lt;p&gt;We captured NAP DHCP Enforcement packet between Vista and Server 2008.&lt;/p&gt;
&lt;p&gt;The data size of Vendor Specific Information in DHCP REQUEST is more than 255, so the data is devided into three parts.&lt;/p&gt;
&lt;p&gt;Private(0xFA) parts are shown as ContinueOption&lt;/p&gt;
&lt;p&gt;and are not parsed at all.&lt;/p&gt;
&lt;p&gt;Please see the parsed data shown below.&lt;/p&gt;
&lt;p&gt; &amp;nbsp;- VendorSpecificInformation: &amp;nbsp;- Type 43&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Code: Vendor specific information, 43(0x2B)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Length: 255 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; - VendorSpecificExtension: NAP-CoID - Type 222&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Code: NAP-CoID, 222(0xDE)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Length: 130 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;CoID: Binary Large Object (130 Bytes)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; - VendorSpecificExtension: NAP-SoH - Type 220&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Code: NAP-SoH, 220(0xDC)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Length: 255 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp;- SOH: Vendor = Microsoft, Version 2, Request&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; - SoHHeader: &lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;- OuterType: 7 (0x7)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Reserved: &amp;nbsp; (00..............)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OuterType: (..00000000000111) Vendor Specific&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Length: 445 (0x1BD)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IANASMICode: Microsoft&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;InnerType: 2 (0x2)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;InnerLength: 437 (0x1B5)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; - SoHModeSubHeader: &lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;- OuterType: 7 (0x7)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Reserved: &amp;nbsp; (00..............)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OuterType: (..00000000000111) Vendor Specific&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Length: 30 (0x1E)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IANASMICode: Microsoft&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CorrelationId: Binary Large Object (24 Bytes)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IntentFlag: Request&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ContentType: 0x0, MUST be set to 0&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; - SSoH: Microsoft, ID = 0&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;- SystemHealthEntityId: SystemHealthId&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Type: 2 (0x2)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mandatory: (0...............) Optional TLV&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Reserved: &amp;nbsp;(.0..............)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;TLVType: &amp;nbsp; &amp;nbsp;(..00000000000010) SystemHealthId&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Length: 4 (0x4)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - SystemHealthId: Microsoft, ID = 0&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VendorCode: Microsoft&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Id: 0 (0x0)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;- VendorSpecificAttribute: VendorSpecific&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Type: 7 (0x7)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mandatory: (0...............) Optional TLV&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Reserved: &amp;nbsp;(.0..............)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;TLVType: &amp;nbsp; &amp;nbsp;(..00000000000111) VendorSpecific&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Length: 89 (0x59)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; VendorID: Microsoft&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - MSVendorSpecificValue: MS-Packet-Info&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AttributeType: MS-Packet-Info&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- MSPacketInfo: 17 (0x11)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Reserved: (000.....)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r: &amp;nbsp; &amp;nbsp; &amp;nbsp;(...1....) Request&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vers: &amp;nbsp; (....0001) 1&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - MSVendorSpecificValue: MS-Machine-Inventory&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AttributeType: MS-Machine-Inventory&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;osVersionMajor: 6 (0x6)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;osVersionMinor: 0 (0x0)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;osVersionBuild: 6001 (0x1771)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;spVersionMajor: 1 (0x1)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;spVersionMinor: 0 (0x0)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;procArch: 0 (0x0)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - MSVendorSpecificValue: MS-MachineName&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AttributeType: MS-MachineName&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;machineNameLenInBytes: 16 (0x10)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;machineName: WIN-VISTA-BU-06&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; - MSVendorSpecificValue: MS-CorrelationId&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AttributeType: MS-CorrelationId&lt;/p&gt;
&lt;p&gt; &amp;nbsp; - VendorSpecificExtension: Unknown Microsoft Extension - Type 73&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Code: Unknown Microsoft Extension, 73(0x49)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;Length: 245 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;MicrosoftUnknownExtensionValue: &lt;/p&gt;
&lt;p&gt;?ﾃ/C6??9b?&lt;/p&gt;
&lt;p&gt;&#x12;?&#x1;?&lt;/p&gt;
&lt;p&gt; &amp;nbsp;- ContinueOption: Continuation Option&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Code: Continuation Option, 250(0xFA)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Length: 255 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; ContinueBlob: :4????&#x2;&lt;/p&gt;
&lt;p&gt; &amp;nbsp;- ContinueOption: Continuation Option&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Code: Continuation Option, 250(0xFA)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Length: 75 UINT8(s)&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; ContinueBlob: U&lt;/p&gt;
&lt;p&gt; &amp;nbsp;- End: &lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; Code: End of Options, 255(0xFF)&lt;/p&gt;
&lt;p&gt;HEX Dump of Vendor specific Information&lt;/p&gt;
&lt;p&gt;0160 &amp;nbsp;79 f9 2b 2b ff de 82 7b 00 34 00 39 00 46 00 35 &amp;nbsp; y.++...{.4.9.F.5&lt;/p&gt;
&lt;p&gt;0170 &amp;nbsp;00 30 00 41 00 45 00 41 00 2d 00 38 00 33 00 32 &amp;nbsp; .0.A.E.A.-.8.3.2&lt;/p&gt;
&lt;p&gt;0180 &amp;nbsp;00 46 00 2d 00 34 00 33 00 33 00 36 00 2d 00 41 &amp;nbsp; .F.-.4.3.3.6.-.A&lt;/p&gt;
&lt;p&gt;0190 &amp;nbsp;00 45 00 44 00 42 00 2d 00 33 00 39 00 36 00 32 &amp;nbsp; .E.D.B.-.3.9.6.2&lt;/p&gt;
&lt;p&gt;01a0 &amp;nbsp;00 42 00 39 00 30 00 41 00 31 00 32 00 33 00 46 &amp;nbsp; .B.9.0.A.1.2.3.F&lt;/p&gt;
&lt;p&gt;01b0 &amp;nbsp;00 7d 00 20 00 2d 00 20 00 32 00 30 00 30 00 38 &amp;nbsp; .}. .-. .2.0.0.8&lt;/p&gt;
&lt;p&gt;01c0 &amp;nbsp;00 2d 00 31 00 30 00 2d 00 33 00 30 00 20 00 30 &amp;nbsp; .-.1.0.-.3.0. .0&lt;/p&gt;
&lt;p&gt;01d0 &amp;nbsp;00 32 00 3a 00 31 00 30 00 3a 00 33 00 36 00 2e &amp;nbsp; .2.:.1.0.:.3.6..&lt;/p&gt;
&lt;p&gt;01e0 &amp;nbsp;00 39 00 38 00 39 00 5a 00 dc ff 00 07 01 bd 00 &amp;nbsp; .9.8.9.Z........&lt;/p&gt;
&lt;p&gt;01f0 &amp;nbsp;00 01 37 00 02 01 b5 00 07 00 1e 00 00 01 37 49 &amp;nbsp; ..7...........7I&lt;/p&gt;
&lt;p&gt;0200 &amp;nbsp;f5 0a ea 83 2f 43 36 ae db 39 62 b9 0a 12 3f 01 &amp;nbsp; ..../C6..9b...?.&lt;/p&gt;
&lt;p&gt;0210 &amp;nbsp;c9 3a 34 b2 d6 b8 d4 01 00 00 02 00 04 00 01 37 &amp;nbsp; .:4............7&lt;/p&gt;
&lt;p&gt;0220 &amp;nbsp;00 00 07 00 59 00 00 01 37 03 11 01 00 00 00 06 &amp;nbsp; ....Y...7.......&lt;/p&gt;
&lt;p&gt;0230 &amp;nbsp;00 00 00 00 00 00 17 71 00 01 00 00 00 00 05 00 &amp;nbsp; .......q........&lt;/p&gt;
&lt;p&gt;0240 &amp;nbsp;10 57 49 4e 2d 56 49 53 54 41 2d 42 55 2d 30 36 &amp;nbsp; .WIN-VISTA-BU-06&lt;/p&gt;
&lt;p&gt;0250 &amp;nbsp;00 06 49 f5 0a ea 83 2f 43 36 ae db 39 62 b9 0a &amp;nbsp; ..I..../C6..9b..&lt;/p&gt;
&lt;p&gt;0260 &amp;nbsp;12 3f 01 c9 fa ff 3a 34 b2 d6 b8 d4 02 00 09 ff &amp;nbsp; .?....:4........&lt;/p&gt;
&lt;p&gt;0270 &amp;nbsp;ff ff ff ff ff ff ff 00 01 00 08 de ca fb ad 01 &amp;nbsp; ................&lt;/p&gt;
&lt;p&gt;0280 &amp;nbsp;00 02 00 04 00 01 37 80 00 07 00 08 00 01 37 80 &amp;nbsp; ......7.......7.&lt;/p&gt;
&lt;p&gt;0290 &amp;nbsp;09 00 00 00 00 07 00 08 00 01 37 80 01 00 06 00 &amp;nbsp; ..........7.....&lt;/p&gt;
&lt;p&gt;02a0 &amp;nbsp;00 08 00 01 00 00 0a 00 24 4d 00 49 00 43 00 52 &amp;nbsp; ........$M.I.C.R&lt;/p&gt;
&lt;p&gt;02b0 &amp;nbsp;00 4f 00 53 00 4f 00 46 00 54 00 20 00 50 00 52 &amp;nbsp; .O.S.O.F.T. .P.R&lt;/p&gt;
&lt;p&gt;02c0 &amp;nbsp;00 4f 00 44 00 55 00 43 00 54 00 00 00 00 0b 00 &amp;nbsp; .O.D.U.C.T......&lt;/p&gt;
&lt;p&gt;02d0 &amp;nbsp;04 00 00 00 06 00 08 00 01 01 00 0a 00 26 53 00 &amp;nbsp; .............&amp;amp;S.&lt;/p&gt;
&lt;p&gt;02e0 &amp;nbsp;79 00 6d 00 61 00 6e 00 74 00 65 00 fa c2 63 00 &amp;nbsp; y.m.a.n.t.e...c.&lt;/p&gt;
&lt;p&gt;02f0 &amp;nbsp;20 00 41 00 6e 00 74 00 69 00 56 00 69 00 72 00 &amp;nbsp; &amp;nbsp;.A.n.t.i.V.i.r.&lt;/p&gt;
&lt;p&gt;0300 &amp;nbsp;75 00 73 00 00 00 00 0b 00 04 00 00 00 03 00 08 &amp;nbsp; u.s.............&lt;/p&gt;
&lt;p&gt;0310 &amp;nbsp;00 01 02 00 0a 00 26 53 00 79 00 6d 00 61 00 6e &amp;nbsp; ......&amp;amp;S.y.m.a.n&lt;/p&gt;
&lt;p&gt;0320 &amp;nbsp;00 74 00 65 00 63 00 20 00 41 00 6e 00 74 00 69 &amp;nbsp; .t.e.c. .A.n.t.i&lt;/p&gt;
&lt;p&gt;0330 &amp;nbsp;00 56 00 69 00 72 00 75 00 73 00 00 00 00 0b 00 &amp;nbsp; .V.i.r.u.s......&lt;/p&gt;
&lt;p&gt;0340 &amp;nbsp;04 00 00 00 03 00 0a 00 24 4d 00 49 00 43 00 52 &amp;nbsp; ........$M.I.C.R&lt;/p&gt;
&lt;p&gt;0350 &amp;nbsp;00 4f 00 53 00 4f 00 46 00 54 00 20 00 50 00 52 &amp;nbsp; .O.S.O.F.T. .P.R&lt;/p&gt;
&lt;p&gt;0360 &amp;nbsp;00 4f 00 44 00 fa 4b 55 00 43 00 54 00 00 00 00 &amp;nbsp; .O.D..KU.C.T....&lt;/p&gt;
&lt;p&gt;0370 &amp;nbsp;0b 00 04 00 00 00 05 00 08 00 01 03 00 0b 00 04 &amp;nbsp; ................&lt;/p&gt;
&lt;p&gt;0380 &amp;nbsp;00 00 00 04 00 08 00 01 04 00 0b 00 04 00 ff 00 &amp;nbsp; ................&lt;/p&gt;
&lt;p&gt;0390 &amp;nbsp;05 00 07 00 08 00 01 37 80 bc 10 32 00 00 07 00 &amp;nbsp; .......7...2....&lt;/p&gt;
&lt;p&gt;03a0 &amp;nbsp;05 00 01 37 80 00 00 07 00 08 00 01 37 80 00 00 &amp;nbsp; ...7........7...&lt;/p&gt;
&lt;p&gt;03b0 &amp;nbsp;02 00 ff &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;...&lt;/p&gt;
</description></item><item><title>re: Open Source Network Monitor Parsers</title><link>http://blogs.technet.com/netmon/archive/2008/09/11/open-source-network-monitor-parsers.aspx#3147469</link><pubDate>Wed, 05 Nov 2008 00:44:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3147469</guid><dc:creator>PaulELong</dc:creator><description>&lt;p&gt;This is exactly the issue I mentioned above. DHCP splits up a payload into fragments in the same packet. &amp;nbsp;This type of fragmentation can't be handled by our engine today.&lt;/p&gt;
&lt;p&gt;It is something on our radar, but it's difficult to say when there will be a built in solution.&lt;/p&gt;
&lt;p&gt;It would be possible to use the NMAPI in NM3.2 to put together the packets and create a new frame or possibly modify the current frame. &amp;nbsp;If you are interested, let me know and I can send you more specifics.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Paul&lt;/p&gt;
</description></item></channel></rss>