Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

MAPI dissector - extend or create?

The MAPI dissector asserts "Exchange 5.5 EMSMDB". Exchange 5.5 was the Win NT 4.0 version, but somewhere in there is a reference to Exchange 2003, and the the dissector is dated 2006 ~ 2007.

But it's not working well with my copy of Win10, and doesn't seem to match the MS MAPI documentation. In particular "static dcerpc_sub_dissector mapi_dissectors[] " only maps opnums from 0 to 9 --- most of which are depreciated -- and doesn't include 10, 11 and 14, which were the opnums used since whenever (MAPI 2 ~ MAPI 23, as documented in MS-OXCRPC 3.14).

It seems to me that the existing MAPI dissector could be extended a bit without breaking anything, but would that be a wrong approach?