Wireshark-users: [Wireshark-users] HTTP filter

From: Andrej van der Zee <andrejvanderzee@xxxxxxxxx>
Date: Thu, 6 Jan 2011 20:59:49 +0900
Hi,

Sorry if this message arrived twice.

Anyway, I was wondering if somebody could tell me how Wireshark decides that a packet has the HTTP protocol. It must do some extra check in addition to testing only for the port number being a standard HTTP port, right?

Thanks,
Andrej