Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] bug in follow TCP ASCII

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Bert van Leeuwen <bert@xxxxxxx>
Date: Thu, 03 Aug 2006 14:10:37 +0200

Hi,

I've discovered a bug in the "follow TCP" ASCII view, it seems to drop
the last payload octet of each packet. See attached capture file, I sent
"0123456789" from client to server, and replied "abcdefghij" from server
to client. In ASCII view on "follow TCP" in wireshark, the "9" and "j"
are missing. They are present in HEX display and C array mode though,
but also seem to be missing (I just noticed now) in RAW and EBCDIC
modes... I'm using:

wireshark version 0.99.2
gentoo linux (everything pretty much latest version)
kernel 2.6.17
gtk 1.2.10

Let me know if you need more info. If you can tell me where the "follow
TCP" code is more or less in the repository I can try fix the bug if you
don't have time.

Regards,
Bert van Leeuwen

Attachment: wireshark_followtcp_break_sample.cap
Description: Binary data

  • Follow-Ups:
    • Re: [Wireshark-dev] bug in follow TCP ASCII
      • From: Jaap Keuter
  • Prev by Date: Re: [Wireshark-dev] wireshark-0.99.2 and OpenBSD 3.9
  • Next by Date: Re: [Wireshark-dev] bug in follow TCP ASCII
  • Previous by thread: Re: [Wireshark-dev] wireshark-0.99.2 and OpenBSD 3.9
  • Next by thread: Re: [Wireshark-dev] bug in follow TCP ASCII
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation