On Sat, Jan 18, 2003 at 06:49:17PM -0000, Graham Turner wrote: > I am attempting to decode the windows 2000 professional startup and logon to > a Windows 2000 Active Directory. > > it seems ethereal (v0.9.8) is reporting "Unknown command:17"
Actually, what it's reporting in the Info column is "Unknown Command:17"; perhaps I should have done a case-insensitive search through the source code, which would've found the NETLOGON dissector - but it'd have found a number of other dissectors. > any info on how this can be more accurately decoded would be gladly > received. It can be more accurately decoded by finding documentation for that packet's format and adding code to the NETLOGON dissector to dissect that packet based on that documentation, or perhaps by having some other packet analyzer decode it (if any do) and having Ethereal dissect it similarly. That will probably happen at some point, but there's no guarantee when it'll happen. _______________________________________________ Ethereal-users mailing list [EMAIL PROTECTED] http://www.ethereal.com/mailman/listinfo/ethereal-users