Ethereal

Re: [Ethereal-dev] smb, dcerpc, having old-style dissector call a tvbuff one?
Google
 
Web Ethereal.com

Home | Introduction | Documentation | Lists | FAQ | Development | Wiki | Bugs

Ethereal-dev: August 2001


On Sun, Jul 22, 2001 at 05:46:39PM +1000, Tim Potter wrote:
> I had most of a patch to do this.  You need to take the uid from
> the sesssetupX packet, the tid from the tconX, and the fid from
> the ntcreateX packet.  This information, plus the existing
> guint32 conversation id gives you a unique tuple that you can
> match to a pipe name.

Will the UID and TID be the same as the ones that appear in the
TRANSACTION SMB that contains the MSRPC messages?

And does the FID appear in the TRANSACTION SMB?  If not, something else
in that SMB must indicate which pipe is being used.



Powered by MHonArc 2.6.10