http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1156
Summary: If a dissector depends on a new datasource created by a
new tvb, that dissector's protocol can't be filtered on.
Product: Wireshark
Version: 0.99.4
Platform: PC
OS/Version: Windows XP
Status: NEW
Severity: Major
Priority: High
Component: Wireshark
AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
ReportedBy: phantal@xxxxxxxxx
Build Information:
I'm not on the computer with the relevant build information. It's 0.99.3,
win32 environment, running in XP media center edition, sp2.
--
If the SSL dissector is used to decrypt encrypted traffic, and the http
dissector then dissects the decrypted SSL data, the new data source created
that the http dissector is able to dissect isn't ever created if 'http' is
filtered on.
STR:
1) Setup the SSL dissector to dissect http packets on port 443.
2) Collect some SSL traffic between the browser/server.
3) Once the capture is complete, in the view filter type 'http' and hit enter.
Results: All packets in the view disapear.
This is making it very hard to work with the packet list when there is a lot
of packets captured. The only workaround (which I don't consider to be a
'reasonable workaround' because it's not a convenient method of dealing with
the problem when you have a large set of packets to deal with) is to sort by
packet name then scroll to where the appropriate protocol is listed.
--
Configure bugmail: http://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.