“bad2.tcpdump.052705″ appears to be damaged or corrupt. It is a Nokia libpcap (tcp dump) capture file. It contains a bogus savefile header. The error occurred after reading 1 packets from the file bad2.052605, link-type EN10MB(Ethernet) An error occurred while reading the file’s record that’s not valid. The file has 1701147252-byte packet, bigger than the maximum packet size of 65535. It has been sent to RedHat Linux 6.1 and SuSE Linux 63.”]
Source: https://taosecurity.blogspot.com/2005/07/excerpt-from-network-forensics-chapter.html

