Hi all,

I'm using Wireshark version 1.2.1 in Ubuntu 9.04 machine. I've taken some of
the captures while communicating my organization's Exchange Server 2007. In
all the captures for MAPI EcDoRpc Request packets, there is a chunk of data
that is pointed out by a field *SubContent Data Size*, and the field after
that *Decrypted MAPI PDU* that points to a different set of data outside the
packet.
Does Decrypted MAPI PDU is the decrypted version of the subcontent field ?
Kindly explain.

-- 
Thanks & Regards,
Soumitra
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <[email protected]>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:[email protected]?subject=unsubscribe

Reply via email to