Why doesn Wireshark show Yahoo Messenger packets in captures that contain Yahoo Messenger traffic?
Wireshark only recognizes as Yahoo Messenger traffic packets to or from TCP port 3050 that begin with “YPNS”, “YHOO”, or “YMSG”. TCP segments that start with the middle of a Yahoo Messenger packet that takes more than one TCP segment will not be recognized as Yahoo Messenger packets (even if the TCP segment also contains the beginning of another Yahoo Messenger packet). 12.
Related Questions
- When I use Wireshark to capture packets, why do I see only packets to and from my machine, or not see all the traffic Im expecting to see from or to the machine Im trying to monitor?
- I want to sniff the network traffic using RAW packets just like Ethereal or Wireshark. Is this possible?
- Why doesn Ethereal show Yahoo Messenger packets in captures that contain Yahoo Messenger traffic?