Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 4652] Unable to decode IBM's Websphere MQ traffic

Date: Mon, 12 Apr 2010 07:25:32 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4652

--- Comment #5 from Andre Luyer <wiresharkbug@xxxxxxxxxxxxxxxxx> 2010-04-12 16:25:24 CEST ---
I have now a capture with MQ traffic from the initial TCP-SYN. There is
definitely some kind of TLV element there.
It starts with a "0x80 0x2c [ plus 44 bytes ]" and then exchanging some kind of
authentication with several "0x16 0x03 [ 3 byte length ] [ data ]" and "0x14
0x03 0x00 0x00 0x01 0x01" sequences.
Finally recognizable MQ traffic (TSH structures) with the prefix of "0x17 0x03
[ 3 byte length ] [ MQ traffic ]".

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.