Wireshark-dev: Re: [Wireshark-dev] How is wireshark unpacking SMB Packets?
From: Richard Sharpe <realrichardsharpe@xxxxxxxxx>
Date: Mon, 5 Feb 2018 05:08:10 -0800
On Sun, Feb 4, 2018 at 11:49 PM, senaps <gerdakan.sa@xxxxxxxxx> wrote:
> Hi all, smb is reading and unpacking packets sent/recived by a smb server.
> it unpacks NTLM hashes and shows the username, network name and stuff like
> that.
> i need to take a look at the source code of wireshark for this part.

Well, the source code is all there in epan/dissectors/packet-smb.c and
packet-smb2.c etc.

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)