[prev in list] [next in list] [prev in thread] [next in thread] 

List:       wireshark-bugs
Subject:    [Wireshark-bugs] [Bug 13866] New: NBAP over SCTP heuristic dissector required
From:       bugzilla-daemon () wireshark ! org
Date:       2017-06-30 14:35:18
Message-ID: bug-13866-15 () https ! bugs ! wireshark ! org/bugzilla/
[Download RAW message or body]

--14988333180.FA4d.31485
Date: Fri, 30 Jun 2017 14:35:18 +0000
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: https://bugs.wireshark.org/bugzilla/
Auto-Submitted: auto-generated

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13866

            Bug ID: 13866
           Summary: NBAP over SCTP heuristic dissector required
           Product: Wireshark
           Version: unspecified
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: Enhancement
          Priority: Low
         Component: Dissection engine (libwireshark)
          Assignee: bugzilla-admin@wireshark.org
          Reporter: sswsdev@gmail.com
  Target Milestone: ---

Created attachment 15666
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=15666&action=edit
DifferentPPIDs

Build Information:

--
Currently the NBAP dissector is only called for PPID 25 in SCTP or when the
user chooses 'decode as' for other PPIDs.
Some vendors choose to send NBAP over other PPIDs, like 17,4 or even 0
Wireshark can heuristically dissect other ASN.1 based protocols like RANAP so
there's probably a way to recognize NBAP as well.

Attached is an example of a capture with NBAP going over PPID 25 from RNC and
over PPID 4 from the Node B (in the same link)

-- 
You are receiving this mail because:
You are watching all bug changes.
--14988333180.FA4d.31485
Date: Fri, 30 Jun 2017 14:35:18 +0000
MIME-Version: 1.0
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: https://bugs.wireshark.org/bugzilla/
Auto-Submitted: auto-generated

<html>
    <head>
      <base href="https://bugs.wireshark.org/bugzilla/" />
      <style>
        body, th, td {
            font-size: 12px;
            font-family: Arial, Helvetica, sans-serif; }
        p, pre { margin-top: 1em; }
        pre {
            font-family: Bitstream Vera Sans Mono, Consolas, Lucida Console, \
monospace;  white-space: pre-wrap;
	}
        table { border: 0; border-spacing: 0; border-collapse: collapse; }
        th, td {
            padding: 0.25em;
            padding-left: 0.5em;
            padding-right: 0.5em;
        }
        th { background: rgb(240, 240, 240); }
        th.th_top { border-bottom: 1px solid rgb(116, 126, 147); }
        th.th_left { border-right: 1px solid rgb(116, 126, 147); }
        td.removed { background-color: #ffcccc; }
        td.added { background-color: #e4ffc7; }
      </style>
    </head>
    <body><table>
        <tr>
          <th class="th_left">Bug ID</th>
          <td><a class="bz_bug_link 
          bz_status_UNCONFIRMED "
   title="UNCONFIRMED - NBAP over SCTP heuristic dissector required"
   href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13866">13866</a>
          </td>
        </tr>

        <tr>
          <th class="th_left">Summary</th>
          <td>NBAP over SCTP heuristic dissector required
          </td>
        </tr>

        <tr>
          <th class="th_left">Product</th>
          <td>Wireshark
          </td>
        </tr>

        <tr>
          <th class="th_left">Version</th>
          <td>unspecified
          </td>
        </tr>

        <tr>
          <th class="th_left">Hardware</th>
          <td>All
          </td>
        </tr>

        <tr>
          <th class="th_left">OS</th>
          <td>All
          </td>
        </tr>

        <tr>
          <th class="th_left">Status</th>
          <td>UNCONFIRMED
          </td>
        </tr>

        <tr>
          <th class="th_left">Severity</th>
          <td>Enhancement
          </td>
        </tr>

        <tr>
          <th class="th_left">Priority</th>
          <td>Low
          </td>
        </tr>

        <tr>
          <th class="th_left">Component</th>
          <td>Dissection engine (libwireshark)
          </td>
        </tr>

        <tr>
          <th class="th_left">Assignee</th>
          <td>bugzilla-admin&#64;wireshark.org
          </td>
        </tr>

        <tr>
          <th class="th_left">Reporter</th>
          <td>sswsdev&#64;gmail.com
          </td>
        </tr>

        <tr>
          <th class="th_left">Target Milestone</th>
          <td>---
          </td>
        </tr></table>
      <p>
        <div>
        <pre>Created <span class=""><a href="attachment.cgi?id=15666" \
name="attach_15666" title="DifferentPPIDs">attachment 15666</a> <a \
href="attachment.cgi?id=15666&amp;action=edit" \
title="DifferentPPIDs">[details]</a></span> DifferentPPIDs

Build Information:

--
Currently the NBAP dissector is only called for PPID 25 in SCTP or when the
user chooses 'decode as' for other PPIDs.
Some vendors choose to send NBAP over other PPIDs, like 17,4 or even 0
Wireshark can heuristically dissect other ASN.1 based protocols like RANAP so
there's probably a way to recognize NBAP as well.

Attached is an example of a capture with NBAP going over PPID 25 from RNC and
over PPID 4 from the Node B (in the same link)</pre>
        </div>
      </p>


      <hr>
      <span>You are receiving this mail because:</span>

      <ul>
          <li>You are watching all bug changes.</li>
      </ul>
    </body>
</html>
--14988333180.FA4d.31485--


[Attachment #3 (text/plain)]

___________________________________________________________________________
Sent via:    Wireshark-bugs mailing list <wireshark-bugs@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
             mailto:wireshark-bugs-request@wireshark.org?subject=unsubscribe

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic