ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] HTTP not decoded

From: Srivats P <pstavirs@xxxxxxxxx>
Date: Wed, 3 Nov 2010 21:00:49 +0530
Hi,

Wireshark does not seem to decode TCP port 80 as HTTP for the attached
pcap file - instead it shows the HTTP data as "TCP segment data".

Is this expected behaviour? Is it because the file does not contain
the TCP handshake packets?

Using Wireshark Version 1.2.1 (SVN Rev 29141) on Windows.

Regards,
Srivats

Attachment: sample.pcap
Description: Binary data