Wireshark-users: [Wireshark-users] Problem with a "Decode As"
From: "Tuc at T-B-O-H.NET" <[email protected]>
Date: Thu, 21 Sep 2006 22:04:27 -0400 (EDT)
Hi,

	From a W2K server I used WinDump to capture some packets,
then switched to a FreeBSD server to display them via Wireshark.

	I'm trying to decode an NTLMSSP session, but it doesn't seem
to be recognizing the packets as such. If I go into "Decode As",
it does bring up "Link/Network/Transport/DCE-RPC", but I don't find
anything in the scroll box that would allow me to decode my packets.

	Am I going about it wrong? Is there something I need to
set first?

		Thanks, Tuc