I have updated ethereal and renamed opcode 0x0b to Ioctl.
It also dissects the 32bit function code into the 4 bitfields
device/access/function/method
It still remains to add documentation for the payload for all the
known ioctl pdu's which will take quite some time.
I will start adding that to ethereal and the wiki but help from the
alleged cifs community is always welcome.
since this is the ioctl opcode it would not be unreasonable to assume
that the two flags field in the smb ioctl call are also present
somewhere in the unknown parts of the payload.