ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-dev: [Ethereal-dev] Any chance to get something like "decode as" for DCE-RPC interfac

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Ulf Lamping <ulf.lamping@xxxxxx>
Date: Wed, 18 Aug 2004 20:03:54 +0200
Hi List!

I have an ongoing problem with DCE-RPC (DCOM) calls.

If I couldn't get the context of a DCE-RPC call (because I've missed the "bind" or "alter context" packets), Ethereal can't get a match between the conversation and the corresponding DCE-RPC call dissection.

It would be *very nice* to have the "Decode As" feature for DCE-RPC interfaces, so the user could select a specific RPC interface for a specific conversation.

Had a short look into the decode as dialog, but as I'm not really familiar with the dissection engine, I don't see an easy way to add this feature.

Anyone interested in implementing such a feature, or at least give an estimation how much effort it would be to implement it and how?

Regards, ULFL