Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] ipv6 unknown extension header

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Sake Blok <sake@xxxxxxxxxx>
Date: Fri, 7 Nov 2008 01:47:47 +0100

On Thu, Nov 06, 2008 at 11:23:14AM -0500, Martin d'Anjou wrote:
> > That is how it's supposed to work. Do you have an example of the 
> > contrary? Then please file a bugreport at bugs.wireshark.org.
> 
> This maybe it. I converted it with text2pcap 1.0.3, and loaded it in 
> wireshark 1.0.3. Wireshark cannot find the TCP which starts at offset 0x76 
> below (fa 8e ...):
> 
> 000000 04 72 da 4f 55 7b 00 02
[...]
> 000250 ae 26 5d 7a
> 
> Am I missing something?

Nope, wireshark was ;-)

I committed a patch in SVN 26722 that fixes this issue...

tshark output of your packet with SVN 26722:

[...]
Internet Protocol Version 6
    0110 .... = Version: 6
        [0110 .... = This field makes the filter "ip.version == 6"
possible: 6]
    .... 0000 0000 .... .... .... .... .... = Traffic class: 0x00000000
    .... .... .... 1010 1101 1010 1011 1101 = Flowlabel: 0x000adabd
    Payload length: 542
    Next header: Unknown (0xc6)
    Hop limit: 116
    Source: f50b:f4c3:37c1:3c42:be28:1467:c244:73ab
(f50b:f4c3:37c1:3c42:be28:1467:c244:73ab)
    Destination: 8450:8510:be0e:7732:83be:a572:4fee:e51c
(8450:8510:be0e:7732:83be:a572:4fee:e51c)
Unknown Extension Header
    Next header: TCP (0x06)
    Length: 7 (64 bytes)
Transmission Control Protocol, Src Port: 64142 (64142), Dst Port: 16517
(16517), Seq: 1, Len: 458
    Source port: 64142 (64142)
    Destination port: 16517 (16517)
[...]

Cheers,
    Sake


  • References:
    • Re: [Wireshark-users] ipv6 unknown extension header
      • From: Martin d'Anjou
  • Prev by Date: Re: [Wireshark-users] tshark creates files in temp dir
  • Next by Date: Re: [Wireshark-users] tshark creates files in temp dir
  • Previous by thread: Re: [Wireshark-users] ipv6 unknown extension header
  • Next by thread: Re: [Wireshark-users] ipv6 unknown extension header
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation