Hi,
I dumped a tcp file from MS exchange MAPI. After displayed the data in
a frame, the next one is a decrypted stub data. Does the decrypted
data starts from TCP data section of which is the MAPI data section
only?
Thank you.
Jim
___
Wireshark-users m
Bill,
I don't believe there is in Wireshark. You have to change the datalink
type in the capture file and then setup custom offsets as I described.
Did you try this and have any luck?
--Jim
> -Original Message-
> Can anyone follow up with me on this, is there a way to force a offset
> s