Wireshark doesn't dissect Emails received via POP3

asked 2019-07-05 21:17:37 +0000

updated 2019-07-05 22:40:46 +0000

grahamb gravatar image

The POP3 packets are encrypted with SSL and are ariving on Port 995.I am using the corresponding SSLKEYLOGFILE. Wireshark shows the POP Layer but the Emails are not correctly parsed. "From", "To", "Subject" and so on aren't serperate fields. Also longer messages, that arive as multiple POP packets, aren't reassembled. Apart from the SSLKEYLOGFILE i am only using the "default settings". What am i doing wrong?

edit retag flag offensive close merge delete