This is our old Q&A Site. Please post any new questions and answers at

In my custom dissector i'm having the problem that my dissector isbeing executed on ICMP packages aswell as UDP. In ICMP packages the data is incomplete so the lua script crashes.

To avoid running it on ICMP packages I tried comparing the current protocol to UDP but that crashes Wireshark.

I'm not sure if that is the best way of doing it so I'm open to any other suggestion

function setDefault (t, d)
    local mt = {__index = function () return d end}
    setmetatable(t, mt)


    local protocols = {
        [0] = "RED"

    local directions = {
        [0] = "Rx",
        [1] = "Tx",
        [2] = "RxTx"

    setDefault(protocols, "UNDEFINED")
    setDefault(directions, "UNKNOWN")
    local version = "" -- use this when debugging to increase the number of the parser

    -- declare our protocol
    local gsg_proto = Proto("GSG"..version, "GSG"..version)

    -- create a function to dissect it
    function gsg_proto.dissector(buffer, pinfo, tree)
        message("protocol >"..tostring(pinfo.cols.protocol).."<") -- this works fine
        if tostring(pinfo.cols.protocol) == 'udp' then
            pinfo.cols.protocol = "myproto"
            return true

    gsg_proto:register_heuristic('udp', gsg_proto.dissector)

Wireshark Version 2.0.2 (v2.0.2-0-ga16e22e from master-2.0) Windows 7

asked 25 Mar '16, 06:04

RedX2501's gravatar image

accept rate: 0%

edited 26 Mar '16, 00:39

It should not be possible to cause Wireshark itself to crash merely by using a Lua script, so this is a bug. Please file a bug on this on the Wireshark Bugzilla; please attach your Lua script to the bug.

permanent link

answered 25 Mar '16, 15:00

Guy%20Harris's gravatar image

Guy Harris ♦♦
accept rate: 19%

Are you able to reproduce this? If so would you mind filling the bug? I don't want to create another account for this....

(26 Mar '16, 00:37) RedX2501

I'm not good with Lua, but the C equivalent to what you want is: pinfo->ptype == PT_UDP

So it should be something like: pinfo.port_type == 3 (not sure if PT_ enumeration is accessible in Lua)

permanent link

answered 03 May '16, 14:52

Michael%20Mann's gravatar image

Michael Mann
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 25 Mar '16, 06:04

question was seen: 1,697 times

last updated: 03 May '16, 14:52

p​o​w​e​r​e​d by O​S​Q​A