Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 8991] New: "Request in:" Wireshark created field displays

Date: Mon, 29 Jul 2013 18:09:16 +0000
Bug ID 8991
Summary "Request in:" Wireshark created field displays non valid reference
Classification Unclassified
Product Wireshark
Version 1.10.1
Hardware x86-64
OS Mac OS X 10.8
Status UNCONFIRMED
Severity Minor
Priority Low
Component Wireshark
Assignee [email protected]
Reporter [email protected]

Build Information:
Version 1.10.1 (SVN Rev 50926 from /trunk-1.10)
Built using llvm-gcc 4.2.1 (Based on Apple Inc. build 5658) (LLVM build
2336.9.00).
--
While studying the Wireshark Network Analyst book in the DNS chapter I loaded
the file "fns-errors-partial.pcapng" and introduced the display filter
dns.qry.name == "www.nmap.org".

If we check one by one the DNS queries and answers we can see that all DNS
queries refer to the packet 7 as the one containing the DNS answer. When we
check packet 5 (the first DNS answer) it points us to packet 4 as the one that
triggered this answer. Going back to 4, we say that 4 didn't change it's mind
;-) and still points us to 7.

Packets 6 and 8 they do not provide any reference as to which queries triggered
them.

Maybe I'm lacking knowledge in how to understand the DNS protocol (that is why
I'm reading the book also).

cheers,
Ioannis


You are receiving this mail because:
  • You are watching all bug changes.