Wireshark Lua Dissector - Getting Unparsed data before dissector

117 Views Asked by At

I'm writing a dissector in lua for Wireshark and the only identifier for these packets are in the data that hasn't been parsed yet. I'm just not sure how to get this yet, usually it is in the tvb buffer when using a dissector, but with the other dissectors the IP or Port was the identifier not the data itself.

1

There are 1 best solutions below

2
Christopher Maynard On

If it's available in the data.data field, then you can try to look into that field to see if the data is relevant to your dissector.

For an example of how this might be done, have a look at the Guacamole Post-dissector I wrote and posted on the Wireshark Guacamole wiki page.