Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] HTTP filter

From: David Alanis <canito@xxxxxxxx>
Date: Mon, 03 Jan 2011 22:59:07 -0600
Andrej-

That's a good question.

I know in Wireshark under edit > preferences > protocols > HTTP you
define which ports should be displayed as HTTP in the GUI.

But maybe ultimately the /usr/share/wireshark/services file determines
what port will be treated as that specific type of traffic?

http://wiki.wireshark.org/Hyper_Text_Transfer_Protocol

Cheers-
David


On Mon, 2011-01-03 at 17:17 +0900, Andrej van der Zee wrote:
> Hi,
> 
> 
> I was wondering how wireshark implements the HTTP filter. Does it just
> look at the destination port only?
> 
> 
> Cheers,
> Andrej
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>              mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe