Ethereal-dev: [Ethereal-dev] Windows Remote Desktop protocol dissector?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Jon Andersen <janderse@xxxxxxxxx>
Date: Fri, 24 Mar 2006 13:46:43 -0500
Hi,

I'm interested in a protocol dissector for the Windows Remote Desktop protocol, and wonder if anyone has some tips.

It appears to me that Ethereal doesn't have a protocol dissector that understands the entire protocol. I can "Decode As..." "TPKT", which does decode the outer layers of the protocol (TPKT, ISO 8073, and ISO 8327-1), however, it does not decode the inner layers of the protocol (MCS, SEC, and RDP). If Ethereal can't do this currently, I'm thinking of writing a dissector myself, based on the open source code of the "rdesktop" RDP implementation.

Any ideas?

Thanks,

-Jon Andersen
Graduate Student
734-763-4521 (work)
734-763-8428 (home)
Computer Science & Engineering - Rm 4917
University of Michigan