Ask Your Question
0

DNP Malformed Packets and Write, Unknown

asked 2023-11-02 01:44:35 +0000

Gonzo gravatar image

Hi,

I am trying to understand a DNP3 trace from an Outstation (DNP3 server).

  • Some outstation frames are showing as "Response [Malformed Packet]"
  • Noticing an unexpected "Write, Unknown Object type" from the outstation to the client.

Could this be a dissector error in Wireshark or is this a true protocol implementation error in the outstation?

Regards,

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2023-11-02 05:57:22 +0000

Guy Harris gravatar image

Could this be a dissector error in Wireshark

Yes, it could be.

or is this a true protocol implementation error in the outstation?

It could also be a protocol implementation error.

Submit an issue on the Wireshark issue list, and attach the trace file (pcap/pcapng/etc., not a screenshot) with enough packets in it to show the problem. You can check the "This issue is confidential and should only be visible to team members with at least Reporter access." checkbox if there's information in the packet trace that shouldn't be made public. That way, we can look at the trace to see what the problem is and, if it's a dissector error, figure out how to fix it, and then test the fix by using the trace.

edit flag offensive delete link more

Comments

Thanks Guy. I have submitted the issue and the trace as suggested. https://gitlab.com/wireshark/wireshar...

Gonzo gravatar imageGonzo ( 2023-11-07 05:10:16 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2023-11-02 01:44:35 +0000

Seen: 97 times

Last updated: Nov 02 '23