Slideshow - Ethereal screenshot 2




Note

Screenshot of ethereal

The stuff with the red lines through it is the IP and TCP header.
Blue underlined: FLAP header
2a - Signifies beginning of frame
02 - FLAP channel (0x01 for login, 0x03 for errors, 0x04 for disconnect)
2 byte sequence number
2 byte length of data in contained in the FLAP

Green underlined: SNAC header
2 byte family ID# (this is the "locate" family)
2 byte subtype ID# (this is the user info subtype)
2 bytes of flags
4 byte SNAC ID#

Lots of SNAC data
Screen name, warning level, userinfo TLVs. User info with encoding and charset. Away message with encoding and charset.


Author: Mark Doliner - created with KPresenter