Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] Decrypted stub data

From: "yhchc hce" <webmail.hce@xxxxxxxxx>
Date: Fri, 27 Jul 2007 11:01:21 +1000
Hi,

I dumped a tcp file from MS exchange MAPI. After displayed the data in
a frame, the next one is a decrypted stub data. Does the decrypted
data starts from TCP data section of which is the MAPI data section
only?

Thank you.

Jim