ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 8084] The display filter "tcp.data contains ff:ff:ff:ff" d

Date: Wed, 19 Dec 2012 18:44:59 +0000

changed bug 8084

What Removed Added
CC   [email protected]

Comment # 3 on bug 8084 from
Yeah, I recently ran into this...  problem... recently.  It was slightly
frustrating to find that the ~45 minutes tshark spent looking for a pattern (in
fifty 500 Mb files) in "tcp.data" was wasted because I should have used "frame
contains" (or, it seems, "tcp contains").

But: I'm not sure it's really a bug.  As Chris said, it's quite common/normal
that things handed off to a sub-dissector don't show up as "<dissector>.data". 
OTOH I can certainly understand the confusion...  Hmmm, needs some thought.


You are receiving this mail because:
  • You are watching all bug changes.