Wireshark-dev: Re: [Wireshark-dev] Dissecting Protocol within Decrypted SSL Packets

From: Robert Hogan <robert@xxxxxxxxxxxxxxx>
Date: Mon, 8 Dec 2008 21:28:05 +0000
On Monday 08 December 2008 20:53:19 lists@xxxxxxxxxxxxxxx wrote:
> Hi there,
>
> I have a modified version of the SSL descriptor running (it uses the TLS
> master keys instead of the server's private key). The decoded packets
> contain a protocol (Tor) which I will need to write a separate dissector
> for. Is this possible? Reading the dev READMEs it's not clear to me how
> wireshark would pass off the decoded contents for dissection by another
> dissector or how I ensure it gets invoked.
>
> Any pointers please?
>

As usual I find the answer to my question shortly after asking it:

I need to use ssl_dissector_add ...



Attachment: signature.asc
Description: This is a digitally signed message part.