Wireshark-dev: Re: [Wireshark-dev] Peek at HTTP Headers as Subdissector

From: "Chih Wang" <CWang@xxxxxxxxxxxxxx>
Date: Mon, 28 Jul 2008 13:46:12 -0700
I have a similar need. What I need to see is the original HTTP request
URL. In our system, the payload of the HTTP response will contain
different message types based on the requested type. Is there a way to
get that info from the subdissector?

Regards,
Chih Wang

-----Original Message-----
From: wireshark-dev-bounces@xxxxxxxxxxxxx
[mailto:wireshark-dev-bounces@xxxxxxxxxxxxx] On Behalf Of Guy Harris
Sent: Monday, July 28, 2008 10:37 AM
To: Developer support list for Wireshark
Subject: Re: [Wireshark-dev] Peek at HTTP Headers as Subdissector


On Jul 28, 2008, at 5:59 AM, DeRosa, Anthony wrote:

> I'm writing an HTTP subdissector.  Given that the tvbuff_t passed to  
> an
> HTTP subdissector is a subset of the tvbuff_t that contains the HTTP
> headers, is there any way to peek at the HTTP headers?  In other  
> words,
> is there a way to peek at the parent tvbuff_t, when all you have is a
> subset?

No, there isn't.

What information do you need from the HTTP headers?
_______________________________________________
Wireshark-dev mailing list
Wireshark-dev@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-dev


CONFIDENTIALITY NOTICE: The information contained in this message may be privileged and/or confidential. If you are not the intended recipient, or responsible for delivering this message to the intended recipient, any review, forwarding, dissemination, distribution or copying of this communication or any attachment(s) is strictly prohibited. If you have received this message in error, please notify the sender immediately, and delete it and all attachments from your computer and network.