Wireshark-bugs: [Wireshark-bugs] [Bug 9604] PN-CBA shown because of changing application data
Date: Sun, 29 Dec 2013 22:25:06 +0000

Comment # 4 on bug 9604 from
(In reply to comment #1)

> The Profinet IO dissector heuristic code seems to specifically treat the
> byte as a version (u8CBAVersion) and handles dissection differently if it's
> 0x11.  From what I can tell, this would appear to happen at line 9385 (see:
> http://anonsvn.wireshark.org/viewvc/trunk/plugins/profinet/packet-dcerpc-pn-
> io.c?revision=54250&view=markup) 
> 
> Since I don't have access to the Profinet IO Specifications (at
> http://www.profibus.com/download/specifications-standards/, presumably), I
> can't verify whether this is correct or not.

Unfortunately don't have access either, at least not right now. The only thing
i can say for sure is, that these bytes (in this case) have nothing to do with
PN versions.
It's application data, i'm altering these within the PLC program (first two
bytes from AF FE to 11 00) - all other settings remain unchanged.

Maybe the check for 11 is ok, but then (i guess) the structure is different or
there is some other indication for CBA.


You are receiving this mail because:
  • You are watching all bug changes.