On Sep 16, 2008, at 4:56 PM, Ryerse, Mike (DIS) wrote:
Wireshark 1.0.3 is displaying a specific SSLv3 packet as “Change
Cipher Spec, Encrypted Handshake Message”, while Ethereal 1.1.0
displays it as “Change Cipher Spec, Certificate Request[Malformed
Packet]”.
Normally I would think the newer software is showing it correctly.
I assume that
1) you meant "Wireshark 1.1.0", not "Ethereal 1.1.0" (the last
release that had the name "Ethereal" rather than "Wireshark" was 0.99.1)
and therefore that
2) Wireshark 1.1.0 is the newer software.
Is that the case?