 |
Decodes the Hotline protocol in Wireshark.
A Lua dissector for the classic Hotline client/server protocol. It decodes the
session handshake and transactions, file transfers, tracker traffic, and HTTP
tunnel records; handles TCP segmentation; and exposes useful values as
Wireshark display filters.
-
Recognizes the TRTP / TRTPHOTL session handshake and decodes transaction
headers, transaction types, field headers, and common field values.
-
Reassembles Hotline PDUs split across TCP segments and dissects multiple PDUs
carried in one segment.
-
Correlates transaction replies with requests and reports response frames and
response time.
-
Decodes common string, numeric, date, flag, access-right, file, user, chat,
and news fields while preserving their original bytes.
-
Decodes HTXF transfer setup, flattened FILP file objects, fork metadata,
folder actions, HTRK tracker queries/registrations, and Hotline HTTP tunnel
records.
-
Supports standard ports, TCP/UDP heuristic detection, and Wireshark's
Decode As… workflow for nonstandard ports.
-
Reports truncated, malformed, inconsistent, and oversized data with
Wireshark expert information instead of raising Lua errors.
From the project's README.
No releases to download here yet. See its source code page.
Source code
|
 |