Wireshark mailing list archives

SMB Dissector does not do all it could with SMB when frames do not contain enough data ...


From: Richard Sharpe <realrichardsharpe () gmail com>
Date: Tue, 17 Jul 2012 09:56:00 -0700

Hi folks,

In case anyone feels like dealing with this, I recently grabbed a
large capture, and because I knew it would be large, I limited the
capture size to 196 bytes.

On an NT Create & X we actually get enough info the display most of
the file name being opened, but currently the SMB dissector simply
throws an assertion and does not dissect anything.

I mention this in case anyone has the cycles to look at fixing these
things before I have a go.

Meanwhile, I have a 25GB capture to try to deal with.

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: