This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How can a dissector deal with different versions of a protocol, when the versions can't really be distinguished from the data stream? The version number isn't available in the data stream or any associated control stream, and without the version number, it is often not possible to decode the data correctly.

One way is to try to decode a set of possible versions, and to see which ones look reasonable, but this is very circuitous and prone to mistakes. Is there a way for a dissector to ask the user for this information?

Thanks, Dirk De Schepper

asked 14 Jul '13, 23:30

deschepper's gravatar image

deschepper
6112
accept rate: 0%


If there is no field in the protocol to indicate the protocol version and dissection for the packet is dependent on the protocol version, then you either need to use heuristics on (part of) the packet to determine the version or (if heuristics have a big chance on failing) use a protocol preference.

A protocol preference gives the user the possibility to change the behavior of the protocol dissector by setting one or more preferences. Protocol version could be one of those preferences.

See also: http://anonsvn.wireshark.org/viewvc/trunk/doc/README.dissector?revision=50557 paragraph 2.6

permanent link

answered 14 Jul '13, 23:54

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

Then you can't actually have different dissector settings for different communication sessions you're monitoring? I guess it's the fault of the protocol for not providing version information... Thanks for the answer.

(16 Jul '13, 05:07) deschepper

Nope, that is the downside if information in the packets is not enough to determine the protocol version...

You could use the "Decode As..." functionality to accomplish this if you register both versions of the dissector to the upper layer protocol (which must provide some method of distinguishing each session).

Could you share a tracefile (on www.cloudshark.org) with both versions of the protocol in it so we can have a look if this is feasible?

(16 Jul '13, 14:27) SYN-bit ♦♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×637
×10
×1

question asked: 14 Jul '13, 23:30

question was seen: 1,225 times

last updated: 16 Jul '13, 14:27

p​o​w​e​r​e​d by O​S​Q​A