This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can one determine which version of SMB is being used by looking at the SMB header?

asked 20 Mar '12, 10:13

Janis%20Bishop's gravatar image

Janis Bishop
1222
accept rate: 0%


Yes.

According to Microsoft's [MS-CIFS] specification, the first 4 bytes of the header for an SMB message "MUST contain the 4-byte literal string '\xFF', 'S', 'M', 'B', with the letters represented by their respective ASCII values in the order shown."

According to their [MS-SMB2 specification], the first 4 bytes of the header for an SMB2 message "MUST be (in network order) 0xFE, 'S', 'M', and 'B'."

So the first byte of the message is 0xFF for SMB and 0xFE for SMB2.

permanent link

answered 20 Mar '12, 16:33

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×52

question asked: 20 Mar '12, 10:13

question was seen: 14,804 times

last updated: 20 Mar '12, 16:33

p​o​w​e​r​e​d by O​S​Q​A