Ethereal

[Ethereal-dev] TCP DNS requests are reliably split ... sometimes
Google
 
Web Ethereal.com

Home | Introduction | Documentation | Lists | FAQ | Development | Wiki | Bugs

Ethereal-dev: October 2003


Some Versions of BIND make some of the TCP queries to another server that end up delivering the request in 2 TCP packets.  The first contains a 2 byte packet length for the data contained in the second packet.
 
As a result of this request spanning 2 packets, Ethereal's Disector can't decode the actual request data.  It would be nice if I could select the DNS packet contents and right click and say display as DNS, but that doesn't work.
 
So, aside from getting the affected versions of BIND (and all the depoyed machines) fixed, what can be done to help.
 
Thanks.
 
- Mark Pizzolato

Powered by MHonArc 2.6.10