ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] heuristic Dissector for Dummies

From: Ulf Lamping <ulf.lamping@xxxxxx>
Date: Tue, 09 Sep 2008 23:51:17 +0200
Maynard, Chris schrieb:
Nice job Ulf.
Thanks!
Attached is a small patch with minor formatting changes
and a few XXX's filled in with some additional information.
Applied as SVN 26170 - thanks :-)


I do have one more question/thought about heuristic dissectors as it
pertains to TCP heuristic dissectors though.  Should the
README.heuristic examples be changed to make use of tcp_dissect_pdus()
for TCP-based heuristic dissectors?  In fact, should existing Wireshark
dissectors that currently simply register as TCP heuristic dissectors be
modified so they can take advantage of TCP reassembly?  A quick grep of
epan/dissectors/packet-*.c yields 41 such dissectors.


Well, to be honest I just don't know.

Regards, ULFL