Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Malformed packet when using IPMI RMCP+

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Anders Broman" <a.broman@xxxxxxxxx>
Date: Mon, 11 Dec 2006 00:04:21 +0100


-----Ursprungligt meddelande-----
Från: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] För Stephen Fisher
Skickat: den 9 december 2006 00:34
Till: Community support list for Wireshark
Ämne: Re: [Wireshark-users] Malformed packet when using IPMI RMCP+


On Thu, Dec 07, 2006 at 01:10:44PM -0800, Stephen Fisher wrote:
> On Thu, Dec 07, 2006 at 01:04:58PM -0600, Kota, Sudhindra wrote:
> 
> > I found this on the Wireshark-dev list. I think it is a patch for 
> > Wireshark.
> > 
> > http://www.wireshark.org/lists/wireshark-dev/200606/msg01818.html
> 
> Thanks.  The same patches work on Unix as on Windows.  That patch must 
> have been missed for inclusion in Wireshark.  Unfortunately, your 
> capture file still has 8 malformed packets with this new patch.  I 
> will contact the person who wrote it to see if they still need that 
> patch applied and if they have an updated one by chance that we can 
> put into Wireshark to fix your problem.

>My e-mail to that patch's author bounced, so we probably aren't going to 
>get an updated version of that patch.  When I applied the patch locally 
>and viewed your capture file, there were just as many malformed packets 
>as before so that patch won't help unfortunately.

>Do you have a link to the specifications for that protocol?  With that, 
>someone may have some spare time to change the dissector to work with 
>the traffic you're seeing.
>
>
>Steve

I've checked in a patch that hopefully makes it a bit clearer what's going
on. The spec can be found at http://www.intel.com/design/servers/ipmi/
More work is needed to dissect this trace.

BR
Anders

_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users


  • References:
    • Re: [Wireshark-users] Malformed packet when using IPMI RMCP+
      • From: Stephen Fisher
  • Prev by Date: Re: [Wireshark-users] voip troubleshooting
  • Next by Date: Re: [Wireshark-users] openvpn and packet sniffing
  • Previous by thread: Re: [Wireshark-users] Malformed packet when using IPMI RMCP+
  • Next by thread: Re: [Wireshark-users] Malformed packet when using IPMI RMCP+
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation