Wireshark-users: Re: [Wireshark-users] RTP decoded as DPLAY in V1.0.0

From: "Keith French" <keithfrench@xxxxxxxxxxxxx>
Date: Fri, 11 Apr 2008 22:10:22 +0100
Yes if you disable DPLAY in the "Enabled Protocols", it correctly decodes as RTP.

Now that Bugzilla is back up again, I have entered it as bug 2452.

----- Original Message ----- From: "Stephen Fisher" <stephentfisher@xxxxxxxxx>
To: "Community support list for Wireshark" <wireshark-users@xxxxxxxxxxxxx>
Sent: Friday, April 11, 2008 6:45 PM
Subject: Re: [Wireshark-users] RTP decoded as DPLAY in V1.0.0


On Fri, Apr 11, 2008 at 04:24:00PM +0100, Martin Mathieson wrote:

Like Jaap says, its either on a port that DPLAY thinks indicates DPLAY
traffic, or DPLAY has an over-zealous heuristic dissector that think
its found a DPLAY frame. Did you try to diable the DPLAY dissector as
he suggested?

Dplay is a heuristic dissector that needs to have its heuristics
tightened since this is happening.  I would say that opening a bug with
us is the appropriate course of action while disabling dplay is a
work-around.


Steve

_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users



--------------------------------------------------------------------------------


No virus found in this incoming message.
Checked by AVG.
Version: 7.5.519 / Virus Database: 269.22.12/1374 - Release Date: 11/04/2008 16:59