Ethereal-dev: Re: [Ethereal-dev] Redesign of the WHOLE Ethereal main menu

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Ronnie Sahlberg" <ronnie_sahlberg@xxxxxxxxxxxxxx>
Date: Sun, 30 Nov 2003 12:30:29 +1100
In order to identify DCERPC protocols, we MUST remember the state associated
with the context identifier from
the previous DCERPC BIND call.

In order to recognize RTP we need to remember state from the H.245 protocol.

In order to recognize something as H.245 we must remember state from the
H.225 protocol.

In order to recognize that something is a ONC-RPC Reply (NFS etc) we must
remember state from the previous
matching ONCRPC Call.

If we dont track state it is not possible to dissect a large number of
protocols.

etc etc.


----- Original Message ----- 
From: "Blue Boar"
Sent: Sunday, November 30, 2003 9:20 AM
Subject: Re: [Ethereal-dev] Redesign of the WHOLE Ethereal main menu


> Guy Harris wrote:
> > Sometimes the state needed to dissect a packet doesn't come from other
> > packets in the same TCP segment, even if the protocol in question
> > happens to be running atop TCP (which, as per "Won't work for UDP, I
> > suppose", isn't necessarily the case).
>
> Strange.  Like what?  DNS names?
>
> BB
>
> _______________________________________________
> Ethereal-dev mailing list
> Ethereal-dev@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-dev