https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15145
Bug ID: 15145
Summary: Gnutella dissector is overly aggressive.
Product: Wireshark
Version: unspecified
Hardware: x86
OS: Mac OS X 10.4
Status: UNCONFIRMED
Severity: Major
Priority: Low
Component: Dissection engine (libwireshark)
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: ---
Created attachment 16621
--> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=16621&action=edit
HTTP traffic over localhost:6346
Build Information:
Version 2.9.0 (v2.9.0rc0-1940-geb9d12a7)
Copyright 1998-2018 Gerald Combs <[email protected]> and contributors.
License GPLv2+: GNU GPL version 2 or later
<http://www.gnu.org/licenses/old-licenses/gpl-2.0.html> This is free software;
see the source for copying conditions. There is NO warranty; not even for
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (64-bit) with Qt 5.9.6, with libpcap, without POSIX capabilities, with
GLib 2.56.1, with zlib 1.2.11, with SMI 0.5.0, with c-ares 1.14.0, with Lua
5.1.5, with GnuTLS 3.5.18, with Gcrypt 1.8.2, with MIT Kerberos, with MaxMind
DB resolver, with nghttp2 1.32.0, with LZ4, with Snappy, with libxml2 2.9.4,
with QtMultimedia, without SBC, with SpanDSP, without bcg729.
Running on Mac OS X 10.13.6, build 17G65 (Darwin 17.7.0), with Intel(R)
Core(TM) i7-4870HQ CPU @ 2.50GHz (with SSE4.2), with 16384 MB of physical
memory, with locale en_US.UTF-8, with libpcap version 1.8.1 -- Apple version
79.20.1, with GnuTLS 3.5.18, with Gcrypt 1.8.2, with zlib 1.2.11, binary
plugins supported (14 loaded). Built using clang 4.2.1 Compatible Apple LLVM
10.0.0 (clang-1000.11.45.2).
--
The Gnutella dissector doesn't have any heuristics in place to reject
non-Gnutella traffic, so it claims all TCP traffic on port 6346. I can
replicate the issue here by doing the following:
1. Run `python -m SimpleHTTPServer 6346`
2. Start a capture on the loopback interface.
3. Run `curl http://127.0.0.1:6346`
--
You are receiving this mail because:
You are watching all bug changes.___________________________________________________________________________
Sent via: Wireshark-bugs mailing list <[email protected]>
Archives: https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
mailto:[email protected]?subject=unsubscribe