Wireshark-dev: [Wireshark-dev] dissection of a malformed RTSP/SDP packet

From: Toralf Förster <toralf.foerster@xxxxxx>
Date: Sun, 30 Mar 2008 16:31:38 +0200
Hi,

playing a little bit with the script provided here http://milw0rm.com/exploits/5307
I'm wondering why the dissector "knows" that the last 19 bytes of the attached
packet has to be dissected as RTSP 

-- 
MfG/Sincerely

Toralf Förster
pgp finger print: 7B1A 07F4 EC82 0F90 D4C2 8936 872A E508 7DB6 9DA3

Attachment: rtsp.pcap
Description: application/pcap

Attachment: signature.asc
Description: This is a digitally signed message part.