Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Malformed packet when using IPMI RMCP+

From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Fri, 8 Dec 2006 15:34:16 -0800
On Thu, Dec 07, 2006 at 01:10:44PM -0800, Stephen Fisher wrote:
> On Thu, Dec 07, 2006 at 01:04:58PM -0600, Kota, Sudhindra wrote:
> 
> > I found this on the Wireshark-dev list. I think it is a patch for 
> > Wireshark.
> > 
> > http://www.wireshark.org/lists/wireshark-dev/200606/msg01818.html
> 
> Thanks.  The same patches work on Unix as on Windows.  That patch must 
> have been missed for inclusion in Wireshark.  Unfortunately, your 
> capture file still has 8 malformed packets with this new patch.  I 
> will contact the person who wrote it to see if they still need that 
> patch applied and if they have an updated one by chance that we can 
> put into Wireshark to fix your problem.

My e-mail to that patch's author bounced, so we probably aren't going to 
get an updated version of that patch.  When I applied the patch locally 
and viewed your capture file, there were just as many malformed packets 
as before so that patch won't help unfortunately.

Do you have a link to the specifications for that protocol?  With that, 
someone may have some spare time to change the dissector to work with 
the traffic you're seeing.


Steve