Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: Re: [Wireshark-dev] heuristic Dissector for Dummies

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Ulf Lamping <ulf.lamping@xxxxxx>
Date: Sat, 06 Sep 2008 13:35:00 +0200

Maynard, Chris schrieb:
I think this information would best be placed in the doc/ directory,
either residing in its own README.heuristic file (with a mention of it
from README.developer) or residing directly in README.developer itself,
under its own section.  Wherever it lives, I think it would also be very
useful to include a heuristic dissector code skeleton, just as the
README.developer does now in section 1.2 for normal dissectors.

There may be general interest from the user's perspective, but I think
it's better to keep it simple.  Section 9.4 [of Wireshark-1.0.2] user
guide does a pretty nice job already, I think, although some dissectors,
UDP & TCP for instance, have a preference for controlling whether
heuristic dissectors are tried first or not, so that might also be worth
mentioning in the user guide (or maybe it is and I just didn't see it).

I don't know if that counts as a concrete idea or not, but it's my 2
cents.  (Of course with the exchange rate being so bad these days, it's
probably worth much less than that.)


Hi Chris!

I've just compiled doc/README.heuristic, containing my intro text and your code snippet - plus a little bit of editing.


@all: Feel free to have a look and send improvements ... or even better patches ;-)

Hope this helps,

Regards, ULFL

  • Follow-Ups:
    • Re: [Wireshark-dev] heuristic Dissector for Dummies
      • From: Maynard, Chris
  • Prev by Date: [Wireshark-dev] buildbot failure in Wireshark (development) on Windows-XP-x86
  • Next by Date: Re: [Wireshark-dev] Custom column issues
  • Previous by thread: Re: [Wireshark-dev] heuristic Dissector for Dummies
  • Next by thread: Re: [Wireshark-dev] heuristic Dissector for Dummies
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation