ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] ldap traffic is not parsered properly

From: "Xiaoguang Liu" <syslxg@xxxxxxxxx>
Date: Thu, 19 Oct 2006 15:21:29 +0800
yeah, it works.

Thanks a lot.

On 10/19/06, Graeme Lunt <graeme.lunt@xxxxxxxxx> wrote:
Hi,

On 10/19/06, Xiaoguang Liu <syslxg@xxxxxxxxx> wrote:
> Sorry for missing that info:
> Version 0.99.4-SVN-19585 (SVN Rev 19585) on xp sp2

Basically you have a large LDAP PDU - I had been hit by this previously.

There is a LDAP preference (introduced in 19288)  to set the maximum
expected LDAP PDU size (default is 65535). If you set it to 100000
then Wireshark will decode your capture correctly - well it works for
me.

I'm not sure why the check is there - but maybe we should increase the
default maximum PDU size - or remove the check altogether?

Graeme
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users