{"id":107,"date":"2006-05-22T21:03:36","date_gmt":"2006-05-23T05:03:36","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2006\/05\/22\/tivoconnect-dissector-for-ethereal\/"},"modified":"2006-05-22T21:04:49","modified_gmt":"2006-05-23T05:04:49","slug":"tivoconnect-dissector-for-ethereal","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2006\/05\/22\/tivoconnect-dissector-for-ethereal\/","title":{"rendered":"TiVoConnect dissector for Ethereal"},"content":{"rendered":"<p>Over the weekend, I coded up a protocol dissector in <a href=\"http:\/\/www.ethereal.com\/\">Ethereal<\/a> for the <a href=\"http:\/\/tivo.com\/developer\/i\/TiVoConnectDiscovery.pdf\">TiVoConnect Discovery Protocol<\/a>.  The protocol is very simple, but I still wanted the satisfaction of seeing it listed by name when scanning through my home network captures while debugging <a href=\"http:\/\/galleon.tv\/\">Galleon<\/a>\/<a href=\"http:\/\/www.tivo.com\/\">TiVo<\/a> traffic.<\/p>\n<p>Ethereal has great <a href=\"http:\/\/anonsvn.ethereal.com\/ethereal\/trunk\/doc\/README.developer\">developer<\/a> <a href=\"http:\/\/wiki.ethereal.com\/Development\">documentation<\/a>.  It was easy to find and got me coding right away with a skeleton dissector.  I just love the projects with these kind of to-the-point examples.  The only thing I felt was missing from their README.developer was something showing that the dissector routine could return <code>gboolean<\/code>, letting a dissector reject being attached to a given packet.<\/p>\n<p>There were other clearly written dissectors that I used for reference: <a href=\"http:\/\/anonsvn.ethereal.com\/ethereal\/trunk\/epan\/dissectors\/packet-dns.c\">DNS<\/a>, <a href=\"http:\/\/anonsvn.ethereal.com\/ethereal\/trunk\/epan\/dissectors\/packet-yhoo.c\">Yahoo<\/a>, and <a href=\"http:\/\/anonsvn.ethereal.com\/ethereal\/trunk\/epan\/dissectors\/packet-syslog.c\">Syslog<\/a>.  They seemed to answer most of the more subtle questions I had about rewriting column text, scanning the packet, and dealing with other special cases.<\/p>\n<p>Hopefully the <a href=\"http:\/\/www.ethereal.com\/lists\/ethereal-dev\/200605\/msg00162.html\">patch<\/a> will get accepted.  I even did the <a href=\"http:\/\/wiki.ethereal.com\/FuzzTesting\">randomized<\/a> testing the wiki <a href=\"http:\/\/wiki.ethereal.com\/SendingFilesToEthereal\">recommended<\/a>.  :)<\/p>\n<p style='text-align:left'>&copy; 2006, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the weekend, I coded up a protocol dissector in Ethereal for the TiVoConnect Discovery Protocol. The protocol is very simple, but I still wanted the satisfaction of seeing it listed by name when scanning through my home network captures while debugging Galleon\/TiVo traffic. Ethereal has great developer documentation. It was easy to find and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,7],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/107"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=107"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/107\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}