Wireshark mailing list archives
Re: Packet not reaching dissector
From: Bill Meier <wmeier () newsguy com>
Date: Sat, 08 May 2010 10:05:14 -0400
Craig Bumpstead wrote:
Hi, I've noticed that Frame 2 with the bad header checksum reaches my dissector but Frame 3 with a LEN=0 doesn't actually reach my dissector (Stepping though the code with VS 2008). Is this normal for WireShark?? Note: I have censored the IP's and MAC addresses.
If there's no TCP payload (eg: the packet is just a TCP ack) then there's nothing to dissect beyond TCP. Frame 2 has 6 bytes of TCP payload so your dissector is called. Frame 3 has 0 bytes of TCP payload. Is that the question ? ___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
Current thread:
- What type should I use for 12 byte field in my dissector?? Craig Bumpstead (May 06)
- Re: What type should I use for 12 byte field in my dissector?? Guy Harris (May 06)
- Packet not reaching dissector Craig Bumpstead (May 08)
- Re: Packet not reaching dissector Bill Meier (May 08)
- Packet not reaching dissector Craig Bumpstead (May 08)
- Re: What type should I use for 12 byte field in my dissector?? Guy Harris (May 06)