I assume that you have at least libpcap installed, since wireshark works with it. You might use pcap_open_offline() and pcap_dispatch() in a small c program that dumps the packages one by one to stdout (and use BCD coding so you can read that line by line from perl).
information about the pcap library can be found in wikipedia http://en.wikipedia.org/wiki/Pcap and from there in http://www.tcpdump.org/pcap3_man.html
Just a guess: if you download the libpcap sources, you also might find information about the data format of the pcap files there
In reply to Re: yet another pcap question
by jethro
in thread yet another pcap question
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |