ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] decoding Remote Desktop Protocol

From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Fri, 9 Nov 2007 23:51:54 -0700
On Mon, Oct 29, 2007 at 06:26:23PM +1100, ronnie sahlberg wrote:

> I have commited an initial and very limited X.224 dissector that
> registers TPKT on port 3389 and makes TPKT spawn off this port into
> X.224 instead.
> 
> The X.224 dissector is very incomplete and only really dissects
> CR/CC/DT and only for class 0. But it is good enough for now as a
> start to decode up to and including the X.224 layer for remote
> desktop.

Do we actually need an X.224 dissector in Wireshark?  My understanding
is that the ITU's X.224 recommendation is nearly identical to ISO's 8073
COTP, which Wireshark already supports.


Steve