Wireshark mailing list archives
Re: HTTP filter
From: Jaap Keuter <jaap.keuter () xs4all nl>
Date: Thu, 06 Jan 2011 21:33:26 +0100
On 01/06/2011 12:59 PM, Andrej van der Zee wrote:
Hi, Sorry if this message arrived twice. Anyway, I was wondering if somebody could tell me how Wireshark decides that a packet has the HTTP protocol. It must do some extra check in addition to testing only for the port number being a standard HTTP port, right? Thanks, Andrej
Hi, Yeah, that's basically it. Or the media type is message/http. All details can be found in epan/dissectors/packet-http.c Thanks, Jaap ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- HTTP filter Andrej van der Zee (Jan 03)
- Re: HTTP filter David Alanis (Jan 03)
- Re: HTTP filter Stephen Fisher (Jan 03)
- Re: HTTP filter Stephen Fisher (Jan 03)
- <Possible follow-ups>
- HTTP filter Andrej van der Zee (Jan 06)
- Re: HTTP filter Jaap Keuter (Jan 06)
- Re: HTTP filter David Alanis (Jan 03)