Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] http Content-Encoding: gzip not decoding

From: Sake Blok <sake@xxxxxxxxxx>
Date: Fri, 8 Feb 2008 19:39:28 +0100
On Fri, Feb 08, 2008 at 09:41:16AM -0800, Bob Keyes wrote:

> I've been trying to figure out some weirdness with the
> Amtrak reservations web site, and have applied
> Wireshark to the task. Packets are sniffed, tcp
> streams assembled, but when it comes time to decode
> gzip encoded content, I get nowhere. I am running
> 0.99.6 on Ubuntu Gutsy. I have seen referenced to
> problems with 0.99.6 and 'chunked' content but this
> isn't 'chunked'. What is the proper way to do this
> decoding? Can anyone else replicate the problem? Does
> anyone have suggestions for workarounds?

I just tried to fetch some pages from www.amtrak.com and
all the ones that have "Content-Encoding: gzip\r\n" are
nicely reassembled and decompressed. I think there were
some significant changes to the http-dissector between
WS 0.99.6 and the current release (I use development
build 24225 at the moment). Can you try version 0.99.7 or
maybe even one of the latest development builds?
(see: http://www.wireshark.org/download/automated/ )

Cheers,
    Sake

~