Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: [Ethereal-dev] Wrong definition in SMTP Disector

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Hirsch, Christian" <Christian.Hirsch@xxxxxxxxxxx>
Date: Tue, 11 Oct 2005 12:25:33 +0200
Hi Ethereal-Experts,

If we're searching a ethereal trace with the string "smtp.req.command ==
"RCPT"" not all messages will be found.
If the MTA transfers more than one e-mail in the same TCP session only the
first "message RCPT" will be found.
The other message "Commands" will be defiend as "Message Body".

So the filter works not for these messages.

It seems to be a bug in "packet-smtp.c"

We are using ethereal 0.10.12 on a Fedora Core 3 OS.

Thanks in advance
Christian