Ask Your Question

Revision history [back]

There are generally 2 ways (that I'm aware of) to solve this, either by:

  1. Making use of dissect_tcp_pdus() - refer to Section of the Wireshark Developer's Guide
  2. "Manually" doing what dissect_tcp_pdus() does, either out of necessity or by preference.

I've tried both methods in the past and generally prefer the 2nd of the two options, mainly because I've run into error handling limitations using dissect_tcp_pdus(). If you also want to try the 2nd method, then essentially just follow along with the fpm.lua example provided on the Wireshark Lua Examples Wiki Page under the A dissector tutorial with TCP-reassembly section.