On Mon, Apr 16, 2007 at 07:48:00AM +0200, Kukosa, Tomas wrote:
>
> I think your solution is not workaround but quite standard solution in
> Wireshark.
> As it is not guaranteed that you have captured whole SSL session it is
> better to have good heuristic than to relay upon state information.
OK, that makes sense too! Although my personality would like to see
everything analysed with 100% certaintly, the real world is not
always perfect, and tracesfiles might not always be either...
Let's stick to the currently committed heuristic solution, the
chances of a false malformed packet are deminished by a large factor.
Cheers,
Sake