ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 2528] New: Wireshark generates strange decoding result (ME

Date: Thu, 8 May 2008 04:35:43 -0700 (PDT)
http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2528

           Summary: Wireshark generates strange decoding result (MEGACO)
           Product: Wireshark
           Version: 1.0.0
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Major
          Priority: High
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: zhgutov@xxxxx


Build Information:
Version 1.0.0

Copyright 1998-2008 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GTK+ 2.12.8, with GLib 2.14.6, with WinPcap (version unknown),
with libz 1.2.3, without POSIX capabilities, with libpcre 7.0, with SMI 0.4.5,
with ADNS, with Lua 5.1, with GnuTLS 1.6.1, with Gcrypt 1.2.3, with MIT
Kerberos, with PortAudio V19-devel, with AirPcap.

Running on Windows XP Service Pack 2, build 2600, with WinPcap version 4.0.2
(packet.dll version 4.0.0.1040), based on libpcap version 0.9.5, without
AirPcap.

Built using Microsoft Visual C++ 6.0 build 8804

Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
Sorry of my fantastic english))

Using Wireshark 0.99.3 I can get this packet:

MEGACO
    Version: 1
    MediagatewayID: <company2.com>:2944
    Transaction: Request
    Transaction ID: 2
    Context: NULL
    Command line: AuditValue=ROOT
        Command: AuditValue
        Termination ID: ROOT
        Audit Descriptor: Audit{Media}
            Media Descriptor
    -------------- (RAW text output) ---------------
    MEGACO/1 <company2.com>:2944
    Transaction=2{
     Context=-{
      AuditValue=ROOT{Audit{Media}}
     }

--------

Since Wireshark 0.99.6a I have got this for the same packet:

--------

MEGACO
    MEGACO/1 <company2.com>:2944\n
        Version: 1
        MediagatewayID: <company2.com>:2944
    Transaction=2{
        Transaction: Request
        Transaction ID: 2
    Context=-{
        Context: NULL
    AuditValue=ROOT{
        Command: AuditValue
        Termination ID: ROOT
    Audit{
[Packet size limited during capture: MEGACO truncated]

I say about '\n's, '\t's and other strange things, but not about "[Packet size
limited during capture: MEGACO truncated]".

See attached pcap file (MEGACO packets)...


-- 
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.