This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

SMTP Info Displaying | | | | | |

0

I have trace that is displaying something that I have never seen before in Wireshark. The traffic is all SMTP but the reassembled packets that include multiple previous frames show up in the Wireshark info as:

S: | | | | | | | | | | |

Has anyone ever seen this before?

asked 24 Oct '13, 09:01

jackster's gravatar image

jackster
11112
accept rate: 0%


One Answer:

0

That's emtpy lines (newline) sent by the server. Every | marks a new line. Right-click on any of the SMTP frames and choose Follow TCP Stream and you'll see it.

Regards
Kurt

answered 24 Oct '13, 14:30

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 25 Oct '13, 06:38