This is our old Q&A Site. Please post any new questions and answers at

I have a single TCP flow in a pcap. "Follow --> TCP Stream" seems to be showing the wrong HTTP payload in Wireshark 2.2.1 (Win7-64 SP1). (But all 23 packets seem to be shown correctly; it's just the payload decode that seems to be incorrect.)
alt text alt text

Is this a known bug? I searched but didn't find an existing defect. Anyone else observed something similar?

Note, "Follow --> TCP Stream" does seem to work correctly in Wireshark 2.0.1 (Mac OSX 10.11.6). alt text

asked 17 Oct '16, 09:17

wwwalker's gravatar image

accept rate: 0%

edited 17 Oct '16, 09:23

Looks like you're running into bug 12855.

permanent link

answered 17 Oct '16, 12:30

JeffMorriss's gravatar image

JeffMorriss ♦
accept rate: 27%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 17 Oct '16, 09:17

question was seen: 1,330 times

last updated: 17 Oct '16, 12:30

p​o​w​e​r​e​d by O​S​Q​A