Wireshark-users: Re: [Wireshark-users] Wireshark decode complaining about Malfromedpacket - (bogu

From: "Sake Blok" <sake@xxxxxxxxxx>
Date: Tue, 15 Sep 2009 17:07:32 +0200
Hi Ramji,
 
Which version of Wireshark are you using. My version (Version 1.3.0-SVN-28821) has no problems with your file.
 
Cheers,
    Sake
----- Original Message -----
Sent: Monday, September 14, 2009 5:50 PM
Subject: [Wireshark-users] Wireshark decode complaining about Malfromedpacket - (bogus, payload length ...)

Hi,
 
I was trying to capturing DNS packets using Wireshark, and it gave errors about bogus payload length.
 
For example in the Frame 23 in the dump:
 
  IP length is 324 bytes
  UDP length is 304 bytes
 
However there is a complaint about bogus payload length 49 : Bad length value 304 > IP payload length
 
Any idea why this is coming eventhough the entire packet was captured.  The bytes beyond 49 bytes in the payload are treated as Ethernet trailer packets.
 
Thanks,

Ramji


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe