Re: [Wireshark-dev] regarding Wireshark's TCP plugin

2009-07-14 Thread Guy Harris
On Jul 14, 2009, at 5:59 AM, Selçuk Cevher wrote: > Does Wireshark's TCP plugin only use port numbers No. > or some other additional mechanisms Yes. > to identify the application layer traffic ? ... > If it uses other mechanisms for traffic identification, what are > these ? The

[Wireshark-dev] regarding Wireshark's TCP plugin

2009-07-14 Thread Selçuk Cevher
Hi, Does Wireshark's TCP plugin only use port numbers or some other additional mechanisms to identify the application layer traffic ? To me, using only port numbers does not make sense. If it uses other mechanisms for traffic identification, what are these ? For example, in case of POP3 and SMT