Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-dev: [Wireshark-dev] Tips on using ETT for variable sized data

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "James Gallogly" <jgallogly@xxxxxxxxxxxxxxx>
Date: Tue, 3 Feb 2009 17:31:43 -0500 (EST)

I am writing a dissector for a protocol where a packet contains several different kinds of internal msgs and has 0-N instances of each kind of internal message. I am trying to figure out the best way to set up the etts. (I am new to writing dissectors so maybe I am thinking about it all wrong)

 

 

So within a packet there are message of Type (A,B,C)

 

Just for a simple example A has 2 ints, B has 2 floats, C has one int

 

In this example packet we receive 2 A’s, 1 Bs, and 0 C’s (keep in mind the next packet might be 5 A’s ,0 B’s , 3C’s)

So a given tree might look like this

 

Protocol

+-A

 |  +-A[0]

 |   |  + -int 1 = 1

 |   |  +- int 2 = 2

 |   +-A[1]

 |   |  + -int 1 = 3

 |   |  +- int 2 = 4

+-B

   +-B[0]

       +- float 1 = 5.0

       +- float 2 = 6.0

 

Keep in mind the index for A and B are irrelevant to the data inside them…so int 1 and int 2 might form an “ID” for the A data and float 1 might form an “ID” for the B data.

 

Sorry to talk in abstract I am just trying to not muddle the problem by bringing in my particular Object Model.

 

For now I have an ett value for A, and for B so if you expand just A[0] as you click the other packets youll expand all A[*] trees. It’s a little ugly especially when lists get long. Does any one know of a good example that solves this kind of problem? Am I doing something really dumb?

 

Thanks,

Jim

 

  • Follow-Ups:
    • Re: [Wireshark-dev] Tips on using ETT for variable sized data
      • From: Stephen Fisher
  • Prev by Date: Re: [Wireshark-dev] text output from command line
  • Next by Date: [Wireshark-dev] explicitly stop capture with Tshark
  • Previous by thread: Re: [Wireshark-dev] text output from command line
  • Next by thread: Re: [Wireshark-dev] Tips on using ETT for variable sized data
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation