Wireshark mailing list archives

Re: How is wireshark unpacking SMB Packets?


From: Richard Sharpe <realrichardsharpe () gmail com>
Date: Mon, 5 Feb 2018 05:08:10 -0800

On Sun, Feb 4, 2018 at 11:49 PM, senaps <gerdakan.sa () gmail com> wrote:
Hi all, smb is reading and unpacking packets sent/recived by a smb server.
it unpacks NTLM hashes and shows the username, network name and stuff like
that.
i need to take a look at the source code of wireshark for this part.

Well, the source code is all there in epan/dissectors/packet-smb.c and
packet-smb2.c etc.

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: