Hi,
Does anyone have a Wireshark pcap file with some decrypted UDP packets that contain the UDP checksum. If the input (packets) and the output (checksum) is known, then by trail and error the original UDP checksum formular may be able to be discovered.
The UDP server is sending a bunch of 1's as the checksum calculation is unknown and the soap.exe is then skipping this verfication. So snopping on the packets is pointless as the packets do not contain the original checksum. The nfsw.exe has UDP packets that are encrypted. This creates a problem of their being no test case to find the original formular.







