<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel">
    <title>gmane.network.wireshark.devel</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10721"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10720"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10719"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10718"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10717"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10716"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10715"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10714"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10713"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10712"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10711"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10710"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10709"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10708"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10707"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10706"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10705"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10704"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10703"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.network.wireshark.devel/10702"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10721">
    <title>Re: Making a draft plugin available</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10721</link>
    <description></description>
    <dc:creator>Peter Johansson</dc:creator>
    <dc:date>2008-07-05T14:36:09</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10720">
    <title>Re: Making a draft plugin available</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10720</link>
    <description>

jgroups/COPYING is the GPLv2, so you've taken care of the biggest 
licensing issue there.  Just follow all the constraints in that 
document; there's no licensing issue with making binaries available, as 
long as the source from which the binaries were built is available (lots 
of GPLed software is available in binary form, including Wireshark).
</description>
    <dc:creator>Guy Harris</dc:creator>
    <dc:date>2008-07-04T18:32:30</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10719">
    <title>Making a draft plugin available</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10719</link>
    <description>Hello

I have written a draft version of a plugin for JGroups (see 
http://www.jgroups.org).
The plugin source is freely available at 
http://javagroups.cvs.sourceforge.net/javagroups/wireshark-plugin.
Rather than requiring users to download wireshark, download the plugin 
and then modify the wireshark distribution by hand to incorporate the 
plugin, we would like to make prepared wireshark binaries freely 
available on the  JGroups SourceForge project, complied for a few of the 
most common OSs.

Are there any licensing issues to be taken into account before doing this?

Richard

</description>
    <dc:creator>Richard Achmatowicz</dc:creator>
    <dc:date>2008-07-04T18:04:45</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10718">
    <title>buildbot failure in Wireshark (development) onUbuntu-7.10-x86-64</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10718</link>
    <description>The Buildbot has detected a new failure of Ubuntu-7.10-x86-64 on Wireshark (development).
Full details are available at:
 http://buildbot.wireshark.org/trunk/builders/Ubuntu-7.10-x86-64/builds/65

Buildbot URL: http://buildbot.wireshark.org/trunk/

Buildslave for this Build: ubuntu-7.10-x86

Build Reason: 
Build Source Stamp: HEAD
Blamelist: wmeier

BUILD FAILED: failed shell_8

sincerely,
 -The Buildbot

</description>
    <dc:creator>buildbot-no-reply-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org</dc:creator>
    <dc:date>2008-07-04T16:31:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10717">
    <title>Re: [patch] sparse fix to SSL decryption code</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10717</link>
    <description>hello,

On Fri, 2008-07-04 at 13:30 +0200, Jaap Keuter wrote:

The bug has been filed:

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2681

and a review for the attached patch has been requested.

Cheers,

Paolo

 
 
 --
 Email.it, the professional e-mail, gratis per te: http://www.email.it/f
 
 Sponsor:
 Scopri le tue passioni con Leonardo.it!
* 
 Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=7614&amp;d=4-7
</description>
    <dc:creator>Paolo Abeni</dc:creator>
    <dc:date>2008-07-04T12:56:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10716">
    <title>Re: [patch] sparse fix to SSL decryption code</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10716</link>
    <description>Hi,

Better file a bugreport on bugs.wireshark.org so this won't get lost.

Thanx,
Jaap

Paolo Abeni wrote:

</description>
    <dc:creator>Jaap Keuter</dc:creator>
    <dc:date>2008-07-04T11:30:33</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10715">
    <title>Re: same call</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10715</link>
    <description>I have re-read a previos mail and I think the file I was searching for is packet-skinny.c. CallInfoMessage has the field 'CallIdentifier' but I'm not sure if it is worth for my porposes

I will keep on searching and appreciate any help


María de Fátima Requena Cabot (2488)
+34 91 787 23 00 alhambra-eidos.es
 


-----Mensaje original-----
De: wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org [mailto:wireshark-dev-bounces&lt; at &gt;wireshark.org] En nombre de Maria de Fatima Requena
Enviado el: viernes, 04 de julio de 2008 11:08
Para: Developer support list for Wireshark
Asunto: [Wireshark-dev] same call

Hi again

If you remember I am trying to record skinny calls. I have one problem. When the sniffer is between two telephones, the Call Manager sends the same signaling for both of them, but with different id's, so I am doing tricks to associate both calls and having just one of them into account.

I am trying to find if there is any Skinny message field which lets me know that two different conference i</description>
    <dc:creator>Maria de Fatima Requena</dc:creator>
    <dc:date>2008-07-04T10:07:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10714">
    <title>same call</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10714</link>
    <description>Hi again

If you remember I am trying to record skinny calls. I have one problem. When the sniffer is between two telephones, the Call Manager sends the same signaling for both of them, but with different id's, so I am doing tricks to associate both calls and having just one of them into account.

I am trying to find if there is any Skinny message field which lets me know that two different conference id's belong to the same physical call. Could you please tell me if it does exists or at least in which Wireshark file can I find the structure of all skinny messages?

Thanks in advance


María de Fátima Requena Cabot (2488)
+34 91 787 23 00 alhambra-eidos.es
 

</description>
    <dc:creator>Maria de Fatima Requena</dc:creator>
    <dc:date>2008-07-04T09:07:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10713">
    <title>[patch] sparse fix to SSL decryption code</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10713</link>
    <description>hello,

the attached patch fix some glitches in the ssl decryption code, namely:

- the StringInfo allocator is allowed to return a NULL pointer if the
requested data length is 0

- the cipher_suites table is expanded and many wrong values are now
fixed

- some duplicate code about ssl session state checking is unified into
the proper location

- the ssl session structure is now properly initialize (a couple of
fields where manged in the wrong way)

- added some more verbose debug messages

I tested the new code against the pcap trace available on the web site
and it work properly.

The patch is against svn revision 25668.

cheers,

Paolo

 
 
 --
 Email.it, the professional e-mail, gratis per te: http://www.email.it/f
 
 Sponsor:
 VOGLIA DI VACANZE ? 
* I Costahotels  sono gli alberghi specializzati in tour enogastronomici nell'entroterra Romagnolo. Rimini, Riccione, Misano.
 Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=8034&amp;d=4-7
</description>
    <dc:creator>Paolo Abeni</dc:creator>
    <dc:date>2008-07-04T07:02:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10712">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10712</link>
    <description>
On Jul 3, 2008, at 2:43 PM, Kumar, Hemant wrote:


That's not possible, and there's no workaround.  You have to give  
fields their full name.  If you have several message types with a  
"flags" field, *and* that "flags" field is the same in all those  
message types, you could register a "proto.flags" field, and  
"proto.flags.XXX" fields for the flags in the "flags" field.

As per my earlier mail, displaying the field list as a multi-level  
tree could be done without that.
</description>
    <dc:creator>Guy Harris</dc:creator>
    <dc:date>2008-07-03T22:00:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10711">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10711</link>
    <description>Hello

Thanks!!
Yes I completely agree with you but tcp.flags.syn appears because we have already registered a field with the name tcp.flags.syn.

What I want to know is that whether such a tree like structure which appears in the details pane is possible in the Filter Expression Dialog Box?
And I don't want to register fields like tcp.flags.syn rather register them individually i.e. register flags separately, syn separately and let the wireshark make the filter expression depending upon the selection in the Filter expression dialog box.

I guess this has not been implemented for Filter Expression Box, but still I wanted to know if it is possible to work around.

Thanks
Hemant


-----Original Message-----
From: wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org [mailto:wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org] On Behalf Of Abhik Sarkar
Sent: Thursday, July 03, 2008 1:36 PM
To: Developer support list for Wireshark
Subject: Re: [Wireshark-dev] Query on Field Registration

Isn't </description>
    <dc:creator>Kumar, Hemant</dc:creator>
    <dc:date>2008-07-03T21:43:32</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10710">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10710</link>
    <description>Isn't _something_ like what you want already present. I agree it is
not _exactly_ the same, but it is very similar. Taking your example of
the TCP protocol:
- Select any frame.
- In the Packet Details pane
 - click + to expand the TCP protocol
 - click + to expand the Flags.
- Select a flag of your choice (e.g. SYN)
- Right-click and choose "Prepare a filter &gt; Selected", and
""tcp.flags.syn == X" appears in the display filter field!

Regards,
Abhik.

On Thu, Jul 3, 2008 at 11:09 PM, Kumar, Hemant &lt;kumarh-zC7DfRvBq/JWk0Htik3J/w&lt; at &gt;public.gmane.org&gt; wrote:
</description>
    <dc:creator>Abhik Sarkar</dc:creator>
    <dc:date>2008-07-03T20:36:19</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10709">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10709</link>
    <description/>
    <dc:creator>Martin Corraine (mcorrain</dc:creator>
    <dc:date>2008-07-03T19:57:58</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10708">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10708</link>
    <description/>
    <dc:creator>Kumar, Hemant</dc:creator>
    <dc:date>2008-07-03T19:09:02</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10707">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10707</link>
    <description>

"Appear" where?  Presumably not in the protocol tree, because that's how 
it *does* appear there.  It sounds as if you mean in the "Filter 
Expression" dialog box.


It's not.

We could probably have the code that constructs the tree view in the 
"Filter Expression" dialog box check, if there's a field 
"foo.bar.bletch", whether there's a "foo.bar" field, and, if so, put 
"foo.bar.bletch" into a tree under "foo.bar" rather than at the top level.
</description>
    <dc:creator>Guy Harris</dc:creator>
    <dc:date>2008-07-03T19:09:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10706">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10706</link>
    <description>

Kumar, Hemant wrote:

That's not (currently) possible in the Expression UI.


No, you would have to create many hf_ entries, one for each message + 
parameter combination.  (Personally I think that design would constrain 
the power of the filter mechanism but I don't know what you're doing.)

</description>
    <dc:creator>Jeff Morriss</dc:creator>
    <dc:date>2008-07-03T18:56:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10705">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10705</link>
    <description>Hello Hemant,

I'm still not sure what your trying to do. I'm sorry. Are you having
trouble setting up the trees and subtrees? Or do you want to, when
searching for a particular message type, just display those trees
relating to your search? That I don't think is possible unless you add
more code. Wireshark won't just do that automatically. 

martin

-----Original Message-----
From: wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org
[mailto:wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org] On Behalf Of Kumar, Hemant
Sent: Thursday, July 03, 2008 1:31 PM
To: Developer support list for Wireshark
Subject: Re: [Wireshark-dev] Query on Field Registration

Thanks Martin and Abhik!! For the replies.

But what I am actually looking for is when the user goes for setting
subfields type so as to filter messages of his interest, he should see a
tree structure with subfields beneath the main field.

That is for example for tcp it should not appear as Tcp.flags.cwr
Tcp.flags.ecn Tcp.flags.urg Tcp.f</description>
    <dc:creator>Martin Corraine (mcorrain</dc:creator>
    <dc:date>2008-07-03T18:14:23</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10704">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10704</link>
    <description>Thanks Martin and Abhik!! For the replies.

But what I am actually looking for is when the user goes for setting subfields type so as to filter messages of his interest, he should see a tree structure with subfields beneath the main field.

That is for example for tcp it should not appear as
Tcp.flags.cwr
Tcp.flags.ecn
Tcp.flags.urg
Tcp.flags.ack and so on rather it should appear as

Tcp+
    Flags+
            cwr
            ecn
            urg
          ack

By clicking on the + the subtree should appear

So I don't want to register fields like ged125.service_control rather
Just register Service control which is going to be common to several other messages separately and then relate it to those messages in the dissect_function()while feeding the information from tvb_buffer in to the field. Ofcourse  , this is possible but then in the expression window
simply appears service_control and ged125+
                                                        Service_control.

Please shed some light on this aspect w</description>
    <dc:creator>Kumar, Hemant</dc:creator>
    <dc:date>2008-07-03T17:30:36</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10703">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10703</link>
    <description>Hello Hemant,

The ged125 protocol that I'm finishing right now has a lot of
sub-messages. I would create a field registration of this message type
that has several sub messages below it. So, for instance I can search
"ged125.service_control" for all those messages. Now, if I want to
search for a particular service control I can search by doing this
"ged125.service_control == 20". Below is the field registration. All the
various sub-types are in a value_string array. Hope this helps.

{ &amp;hf_ged125_service_control_MessageSubvalue,
{ "Message value", "ged125.service_control", FT_UINT32,
BASE_DEC,
VALS(vals_service_control_message_subvalues), 0x0,
        "Sub-Service Control Message value", HFILL }}


-Martin


-----Original Message-----
From: wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org
[mailto:wireshark-dev-bounces-IZ8446WsY0/dtAWm4Da02A&lt; at &gt;public.gmane.org] On Behalf Of Abhik Sarkar
Sent: Thursday, July 03, 2008 2:26 AM
To: Developer support list for Wireshark
Subject: Re: [Wireshark-dev] </description>
    <dc:creator>Martin Corraine (mcorrain</dc:creator>
    <dc:date>2008-07-03T12:27:44</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10702">
    <title>Re: Query on Field Registration</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10702</link>
    <description>Hi Hemant,

As far as I know nesting of header fields is not possible... check out
epan/proto.h where the field info structures are defined. What you
could do is something like have:
hf_message_type
hf_field1
hf_field2

Then, the display filter would be "message.type==1 &amp;&amp; field1.value==X"
or "message.type==2 &amp;&amp; field1.value==X). You can then (in the protocol
tree) next the fields under message types by using subtrees... This is
done for the protocol I am most familiar with (SMPP) and you can check
in packet-smpp.c how the common DCS field is handled in a submit_sm
and a data_sm.

HTH
Abhik

On Thu, Jul 3, 2008 at 4:23 AM, Kumar, Hemant &lt;kumarh-zC7DfRvBq/JWk0Htik3J/w&lt; at &gt;public.gmane.org&gt; wrote:
</description>
    <dc:creator>Abhik Sarkar</dc:creator>
    <dc:date>2008-07-03T06:25:36</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.network.wireshark.devel/10701">
    <title>Re: Header file of FIX Protocol</title>
    <link>http://permalink.gmane.org/gmane.network.wireshark.devel/10701</link>
    <description>

This is the dissector for the FIX Protocol:

http://anonsvn.wireshark.org/wireshark/trunk/epan/dissectors/packet-fix.c

It is also included when you download Wireshark source code.


Steve

</description>
    <dc:creator>Stephen Fisher</dc:creator>
    <dc:date>2008-07-03T05:35:53</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.network.wireshark.devel">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.network.wireshark.devel</link>
  </textinput>
</rdf:RDF>
