Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] Help Needed

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Priyadarshi Parida" <priyadarshi.parida@xxxxxxxxxxxxxxxx>
Date: Wed, 6 Feb 2008 16:28:53 +0530

Hi List,

I have some problem in understanding segmentation in protocols in TCP and top of TCP.

 

I have fair idea in networking and protocols stacks n routing but seem I have some confusion.

 

 

When TCP assembles segments:

 

What should be the end condition that TCP should assume and think its done with assembling all segments.

 

I understood that Push flag is useful.

Again I thought may be sequence number is useful.

Not sure what exactly is the right approach for assembling.

 

 

Now some thing at top of TCP, Lets say HTTP.

If HTTP has Content Length than its fine and easy to assemble segments in HTTP, but How if content Length is missing IN HTTP.

How if content length data is distributed in two different frames. I mean we have Hex values for Conte Length: as last values in one segment and value for it lets say 223 in beginning of next segment

 

Any suggestion or pointer on this would be very useful.

 

Br

Priyadarshi.

 

 

  • Follow-Ups:
    • Re: [Wireshark-dev] Help Needed
      • From: Sake Blok
  • Prev by Date: Re: [Wireshark-dev] [Help]Where I can find the wireshark recourses?
  • Next by Date: [Wireshark-dev] nmake -f Makefile.nmake all is failing
  • Previous by thread: Re: [Wireshark-dev] What files are really necessary to modify to add a plug-in?
  • Next by thread: Re: [Wireshark-dev] Help Needed
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation