Wireshark mailing list archives

Re: begginer question , how to decode this response


From: Sake Blok <sake () euronet nl>
Date: Thu, 15 Jul 2010 16:34:17 +0200

On 15 jul 2010, at 14:21, Meir Yanovich wrote:

\im monitoring some http request and getting response that is probbpli encoded and i like to decode the response
how can i do this is wireshark?
here is example when i make follow stream :
[...]
Content-Encoding: gzip

The data you see in the Follow TCP Stream output is RAW TCP data. In this case it's HTTP data, where the response is 
compressed by gzip. Wireshark is able to decompress the data for you. If reassembly is enabled in your preferences, you 
should be able to see the HTTP response unencrypted in the packet details. Unfortunately there is no functionality in 
Wireshark at this time to decompress data in the Follow TCP Stream output.

Cheers,


Sake

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: