>In that case, you'd probably want to make a copy of the packet data, XOR it, and add the XORed data as a new data source for the packet. >The function tacplus_decrypted_tvb_setup() in packet-tacacs.c provides a pretty good (and well-commented) example of this.
That's my weekend ruined then ;-) Thanks for this. Neil The information contained in this communication is intended for the use of the designated recipients named above. If the reader of this communication is not the intended recipient, you are hereby notified that you have received this communication in error, and that any review, dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify The Associated Press immediately by telephone at +44-20-7427-4202 and delete this email. Thank you. [IP_UK_DISC] msk dccc60c6d2c3a6438f0cf467d9a4938 _______________________________________________ Wireshark-users mailing list Wireshark-users@wireshark.org http://www.wireshark.org/mailman/listinfo/wireshark-users