This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

NBSS and smb2 in mid-tcp package

0

Hi. When NBSS session or session smb occurs in the middle of the TCP packet, I can not see them properly in wireshark.alt text How do I can see the analysis of these protocols, if they are in the middle of the tcp packet? I tried to do it using the menu "Decode as...", but nothing happened.!

asked 26 May '16, 05:30

barabashka's gravatar image

barabashka
6112
accept rate: 0%

Working from a screenshot is prohibitively difficult. Can you share a capture in a publicly accessible spot, e.g. CloudShark?

(26 May '16, 05:57) Jaap ♦

Sorry for the long silence;) Here is the link https://www.cloudshark.org/captures/8319b97b6296 I Thank you for your attention to this issue

(06 Jun '16, 01:56) barabashka

@barabashka

I moved your "answer" to a comment under the question when you posted it and then deleted the 2nd "answer" as it was a duplicate.

Please read the site FAQ for more information.

(06 Jun '16, 06:00) grahamb ♦

One Answer:

0

can see the analysis of these protocols, if they are in the middle of the tcp packet?

Currently, no. Wireshark would have to scan through the packet to find the beginning of the SMB2 message (which actually beings with the "NetBIOS SS" data - Wireshark really should be labeling port 445 traffic as SMB, not NBSS, as SMB-over-TCP uses something similar to, but simpler than, NBSS), show the data before it as continuation data, and show the SMB2 message. It currently doesn't do that.

It'd be a lot easier to test and implement it if we had a capture file, just as Jaap suggested.

answered 26 May '16, 15:40

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%