ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] Multiple Packets in One TCP Segment

From: Susan Ditmore <sditmore@xxxxxxxxx>
Date: Fri, 14 Aug 2009 16:56:04 -0400
Hello,

I am developing a packet dissector plugin for Wireshark. The packets I am dissecting do not specify their length in their header, but they are terminated by a special character (and can be a variable length). Additionally, multiple complete packets of the protocol may arrive in one tcp segment. I would like to know how to tell wireshark to divide up these packets. I understand there is a command called tcp_dissect_pdus(), but I believe it needs the length specified in the header. Is this correct?

Sincerely,

Susan Ditmore
--
"To categorize is human; to distribute, divine."