Wireshark 歷史版本列表
Wireshark 是世界上最先進的 Windows 和 Unix 免費網絡協議分析儀,也是許多行業和教育機構的事實上(通常是法律上)的標準。 Wireshark 是由全世界的網絡專家撰寫的,是開源的力量的一個例子。通過它,專業用戶可以完全分析他們的網絡連接,查看捕獲數據的詳細分類,過濾它可以更容易地識別您想要仔細檢查的流程,使用插件分析數據,創建處理數據的腳本,捕獲 VoIP 呼叫或 USB&n... Wireshark 軟體介紹Wireshark (32-bit)Wireshark (64-bit)
更新時間:2016-04-23
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- [1]wnpa-sec-2016-19 The NCP dissector could crash. ([2]Bug 11591)
- [3]wnpa-sec-2016-20 TShark could crash due to a packet reassembly bug. ([4]Bug 11799)
- [5]wnpa-sec-2016-21 The IEEE 802.11 dissector could crash. ([6]Bug 11824, [7]Bug 12187)
- [8]wnpa-sec-2016-22 The PKTC dissector could crash. ([9]Bug 12206)
- [10]wnpa-sec-2016-23 The PKTC dissector could crash. ([11]Bug 12242)
- [12]wnpa-sec-2016-24 The IAX2 dissector could go into an infinite loop. ([13]Bug 12260)
- [14]wnpa-sec-2016-25 Wireshark and TShark could exhaust the stack. ([15]Bug 12268)
- [16]wnpa-sec-2016-26 The GSM CBCH dissector could crash. ([17]Bug 12278)
- [18]wnpa-sec-2016-27 MS-WSP dissector crash. ([19]Bug 12341)
The following bugs have been fixed:
- Protocol Hierarchy Statistics shows LDAP lines recursively. ([20]Bug 1734)
- UTF-8 replacement characters in FT_STRINGs are escaped for presentation. ([21]Bug 10681)
- DTLS : reassembly error, protocol DTLS: New fragment overlaps old data. ([22]Bug 11477)
- Packet byte pane in Qt version of packet window isn't being displayed. ([23]Bug 11760)
- "wireshark -i usbmon2 -k" results in "No interfaces selected" when restarting a capture. ([24]Bug 11939)
- Crash when changing the "which packets to print" radio button in the Print dialog. ([25]Bug 12040)
- Selecting packets causes memory leak. ([26]Bug 12044)
- Client Hello not dissected when failed SSL handshake fully captured. ([27]Bug 12132)
- TCP graphs - wrong stream graphed if stream index > 99. ([28]Bug 12163)
- Typo in packet-gsm_a_dtap.c. ([29]Bug 12186)
- Lua dot file error. ([30]Bug 12196)
- "All Files" does not allow selecting files without period. ([31]Bug 12203)
- wlan, wlan_mgt, Length error shown for IE BSS AC Access Delay/WAPI Parameter Set (68). ([32]Bug 12223)
- Qt GUI very slow when expanding packet details with a lot of items. ([33]Bug 12228)
- Comparing a boolean field against 1 always succeeds on big-endian machines. ([34]Bug 12236)
- FIN flag not always correctly passed to subdissectors. ([35]Bug 12238)
- Interpretation of BGP NLRI for default route cause malformed packet. ([36]Bug 12240)
- Capture Interfaces dialog crashes after clicking the bookmark menu. ([37]Bug 12241)
- Wireshark crashes right after a capture filter is selected. ([38]Bug 12245)
- GSM GMM Identity Response dissection error. ([39]Bug 12246)
- Crash reloading "dissector.lua" from the Wireshark website. ([40]Bug 12251)
- VoIP calls does not show IAX2 calls. ([41]Bug 12254)
- Wireshark CPU usage has dramatically increased. ([42]Bug 12258)
- RPC/NFS incorrectly decodes as ACAP. ([43]Bug 12265)
- Wireshark mistakenly flags CF-End packets as being Malformed. ([44]Bug 12266)
- ASTERIX Category 48 Reserved Expansion Field. ([45]Bug 12267)
- It is not possible to enter characters requiring "Alt Gr" in the display filter box such as "[" on a Swedish keyboard. ([46]Bug 12270)
- tshark crashes when trying to export to pdml. ([47]Bug 12276)
- Build fails on Centos 6.5 with gtk2 in ui/gtk/rtp_player.c rtp_channel_info_r has no no member start_time. ([48]Bug 12277)
- TCP Dissector - spurious retransmissions not always recognized. ([49]Bug 12282)
- PRA Identifier of the IE PRA Action should use 3 octets (6 to 8) and not 2 in GTPv2. ([50]Bug 12284)
- Dissector bug, failed assertion, proto_desegment pinfo->can_desegment. ([51]Bug 12285)
- Colorize with filter, new coloring rule, is labeled as new conversation rule. ([52]Bug 12289)
- Qt Multicast Stream Dialog error in input field Burst alarm threshold and Buffer alarm. ([53]Bug 12309)
- 6LoWPAN reassembly incorrect if extension header padding was elided. ([54]Bug 12310)
- USBPcap prevents keyboard from working. ([55]Bug 12316)
- Crash when reloading Lua script when Field is gone. ([56]Bug 12328)
- Wrong display of USSD strings in the GSM 7-bit alphabet for non-ASCII characters in Wireshark 2.0.x. ([57]Bug 12337)
- Malformed Packet: RTP. ([58]Bug 12339)
- Incorrect error on MPA pdu length on iWARP packets. ([59]Bug 12348)
- Endpoints window doesn't show name resolution. ([60]Bug 12353)
- Updated Protocol Support: 6LoWPAN, ACAP, Asterix, BGP, DMP, DNS, DTLS, EAP, FMTP, GPRS LLC, GSM A, GSM A GM, GSM CBCH, GSM MAP, GTPv2, HTTP, IAX2, IEEE 802.11, iWARP MPA, MS-WSP, MySQL, NCP, NFS, PKTC, QUIC, R3, RTP, SMB, SPRT, TCP, ZEP, ZigBee, ZigBee NWK, ZigBee ZCL SE, and ZVT
New and Updated Capture File Support:
- and Gammu DCT3
更新時間:2016-02-27
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- wnpa-sec-2016-01
- DLL hijacking vulnerability. CVE-2016-2521
- wnpa-sec-2016-02
- ASN.1 BER dissector crash. (Bug 11828) CVE-2016-2522
- wnpa-sec-2016-03
- DNP dissector infinite loop. (Bug 11938) CVE-2016-2523
- wnpa-sec-2016-04
- X.509AF dissector crash. (Bug 12002) CVE-2016-2524
- wnpa-sec-2016-05
- HTTP/2 dissector crash. (Bug 12077) CVE-2016-2525
- wnpa-sec-2016-06
- HiQnet dissector crash. (Bug 11983) CVE-2016-2526
- wnpa-sec-2016-07
- 3GPP TS 32.423 Trace file parser crash. (Bug 11982) CVE-2016-2527
- wnpa-sec-2016-08
- LBMC dissector crash. (Bug 11984) CVE-2016-2528
- wnpa-sec-2016-09
- iSeries file parser crash. (Bug 11985) CVE-2016-2529
- wnpa-sec-2016-10
- RSL dissector crash. (Bug 11829) CVE-2016-2530 CVE-2016-2531
- wnpa-sec-2016-11
- LLRP dissector crash. (Bug 12048) CVE-2016-2532
- wnpa-sec-2016-12
- Ixia IxVeriWave file parser crash. (Bug 11795)
- wnpa-sec-2016-13
- IEEE 802.11 dissector crash. (Bug 11818)
- wnpa-sec-2016-14
- GSM A-bis OML dissector crash. (Bug 11825)
- wnpa-sec-2016-15
- ASN.1 BER dissector crash. (Bug 12106)
- wnpa-sec-2016-16
- SPICE dissector large loop. (Bug 12151)
- wnpa-sec-2016-17
- NFS dissector crash.
- wnpa-sec-2016-18
- ASN.1 BER dissector crash. (Bug 11822)
The following bugs have been fixed:
- HTTP 302 decoded as TCP when "Allow subdissector to reassemble TCP streams" option is enabled. (Bug 9848)
- Questionable calling of ethernet dissector by encapsulating protocol dissectors. (Bug 9933)
- Qt & Legacy & probably TShark too] Delta Time Conversation column is empty. (Bug 11559)
- extcap: abort when validating capture filter for DLT 147. (Bug 11656)
- Missing columns in Qt Flow Graph. (Bug 11710)
- Interface list doesn’t show well when the list is very long. (Bug 11733)
- Unable to use saved Capture Filters in Qt UI. (Bug 11836)
- extcap: Capture interface options snaplen, buffer and promiscuous not being used. (Bug 11865)
- Improper RPC reassembly (Bug 11913)
- GTPv1 Dual Stack with one static and one Dynamic IP. (Bug 11945)
- Wireshark 2.0.1 MPLS dissector not decoding payload when control word is present in pseudowire. (Bug 11949)
- "…using this filter" turns white (not green or red). Plus dropdown arrow does nothing. (Bug 11950)
- EIGRP field eigrp.ipv4.destination does not show the correct destination. (Bug 11953)
- tshark -z conv,type[,filter] swapped frame / byte values from / to columns. (Bug 11959)
- The field name nstrace.tcpdbg.tcpack should be nstrace.tcpdbg.tcprtt. (Bug 11964)
- 6LoWPAN IPHC traffic class not decompressed correctly. (Bug 11971)
- Crash with snooping NFS file handles. (Bug 11972)
- 802.11 dissector fails to decrypt some broadcast messages. (Bug 11973)
- Wireshark hangs when adding a new profile. (Bug 11979)
- Issues when closing the application with a running capture without packets. (Bug 11981)
- New Qt UI lacks ability to step through multiple TCP streams with Analyze > Follow > TCP Stream. (Bug 11987)
- GTK: plugin_if_goto_frame causes Access Violation if called before capture file is loaded. (Bug 11989)
- Wireshark 2.0.1 crash on start. (Bug 11992)
- Wi-Fi 4-way handshake 4/4 is displayed as 2/4. (Bug 11994)
- ACN: acn.dmx.data has incorrect type. (Bug 11999)
- editcap packet comment won’t add multiple comments. (Bug 12007)
- DICOM Sequences no longer able to be expanded. (Bug 12011)
- Wrong TCP stream when port numbers are reused. (Bug 12022)
- SSL decryption fails in presence of a Client certificate. (Bug 12042)
- LUA: TVBs backing a data source is freed too early. (Bug 12050)
- PIM: pim.group filter have the same name for IPv4 and IPv6. (Bug 12061)
- Failed to parse M3AP IE (TNL information). (Bug 12070)
- Wrong interpretation of Instance ID value in OSPFv3 packet. (Bug 12072)
- MP2T Dissector does parse RTP properly in 2.0.1. (Bug 12099)
- editcap does not adjust time for frames with absolute timestamp 0 < t < 1 secs. (Bug 12116)
- Guard Interval is not consistent between Radiotap & wlan_radio. (Bug 12123)
- Calling dumpcap -i- results in access violation. (Bug 12143)
- Qt: Friendly Name and Interface Name columns should not be editable. (Bug 12146)
- PPTP GRE call ID not always decoded. (Bug 12149)
- Interface list does not show device description anymore. (Bug 12156)
- Find Packet does not highlight the matching tree item or packet bytes. (Bug 12157)
- "total block length … is too large" error when opening pcapng file with multiple SHB sections. (Bug 12167)
- http.request.full_uri is malformed if an HTTP Proxy is used. (Bug 12176)
- SNMP dissector fails at msgSecurityParameters with long length encoding. (Bug 12181)
- Windows installers and PortableApps® packages are now dual signed using SHA-1 and SHA-256 in order to comply with Microsoft Authenticode policy. Windows 7 and Windows Server 2008 R2 users should ensure that update 3123479 is installed. Windows Vista and Windows Server 2008 users should ensure that hotfix 2763674 is installed.
Updated Protocol Support:
- 6LoWPAN, ACN, ASN.1 BER, BATADV, DICOM, DNP3, DOCSIS INT-RNG-REQ, E100, EIGRP, GSM A DTAP, GSM SMS, GTP, HiQnet, HTTP, HTTP/2, IEEE 802.11, IKEv2, InfiniBand, IPv4, IPv6, LBMC, LLRP, M3AP, MAC LTE, MP2T, MPLS, NFS, NS Trace, OSPF, PIM, PPTP, RLC LTE, RoHC, RPC, RSL, SNMP, SPICE, SSL, TCP, TRILL, VXLAN, WaveAgent, and X.509AF
New and Updated Capture File Support:
- 3GPP TS 32.423 Trace, iSeries, Ixia IxVeriWave, pcap, and pcapng
更新時間:2016-02-27
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- wnpa-sec-2016-01
- DLL hijacking vulnerability. CVE-2016-2521
- wnpa-sec-2016-02
- ASN.1 BER dissector crash. (Bug 11828) CVE-2016-2522
- wnpa-sec-2016-03
- DNP dissector infinite loop. (Bug 11938) CVE-2016-2523
- wnpa-sec-2016-04
- X.509AF dissector crash. (Bug 12002) CVE-2016-2524
- wnpa-sec-2016-05
- HTTP/2 dissector crash. (Bug 12077) CVE-2016-2525
- wnpa-sec-2016-06
- HiQnet dissector crash. (Bug 11983) CVE-2016-2526
- wnpa-sec-2016-07
- 3GPP TS 32.423 Trace file parser crash. (Bug 11982) CVE-2016-2527
- wnpa-sec-2016-08
- LBMC dissector crash. (Bug 11984) CVE-2016-2528
- wnpa-sec-2016-09
- iSeries file parser crash. (Bug 11985) CVE-2016-2529
- wnpa-sec-2016-10
- RSL dissector crash. (Bug 11829) CVE-2016-2530 CVE-2016-2531
- wnpa-sec-2016-11
- LLRP dissector crash. (Bug 12048) CVE-2016-2532
- wnpa-sec-2016-12
- Ixia IxVeriWave file parser crash. (Bug 11795)
- wnpa-sec-2016-13
- IEEE 802.11 dissector crash. (Bug 11818)
- wnpa-sec-2016-14
- GSM A-bis OML dissector crash. (Bug 11825)
- wnpa-sec-2016-15
- ASN.1 BER dissector crash. (Bug 12106)
- wnpa-sec-2016-16
- SPICE dissector large loop. (Bug 12151)
- wnpa-sec-2016-17
- NFS dissector crash.
- wnpa-sec-2016-18
- ASN.1 BER dissector crash. (Bug 11822)
The following bugs have been fixed:
- HTTP 302 decoded as TCP when "Allow subdissector to reassemble TCP streams" option is enabled. (Bug 9848)
- Questionable calling of ethernet dissector by encapsulating protocol dissectors. (Bug 9933)
- Qt & Legacy & probably TShark too] Delta Time Conversation column is empty. (Bug 11559)
- extcap: abort when validating capture filter for DLT 147. (Bug 11656)
- Missing columns in Qt Flow Graph. (Bug 11710)
- Interface list doesn’t show well when the list is very long. (Bug 11733)
- Unable to use saved Capture Filters in Qt UI. (Bug 11836)
- extcap: Capture interface options snaplen, buffer and promiscuous not being used. (Bug 11865)
- Improper RPC reassembly (Bug 11913)
- GTPv1 Dual Stack with one static and one Dynamic IP. (Bug 11945)
- Wireshark 2.0.1 MPLS dissector not decoding payload when control word is present in pseudowire. (Bug 11949)
- "…using this filter" turns white (not green or red). Plus dropdown arrow does nothing. (Bug 11950)
- EIGRP field eigrp.ipv4.destination does not show the correct destination. (Bug 11953)
- tshark -z conv,type[,filter] swapped frame / byte values from / to columns. (Bug 11959)
- The field name nstrace.tcpdbg.tcpack should be nstrace.tcpdbg.tcprtt. (Bug 11964)
- 6LoWPAN IPHC traffic class not decompressed correctly. (Bug 11971)
- Crash with snooping NFS file handles. (Bug 11972)
- 802.11 dissector fails to decrypt some broadcast messages. (Bug 11973)
- Wireshark hangs when adding a new profile. (Bug 11979)
- Issues when closing the application with a running capture without packets. (Bug 11981)
- New Qt UI lacks ability to step through multiple TCP streams with Analyze > Follow > TCP Stream. (Bug 11987)
- GTK: plugin_if_goto_frame causes Access Violation if called before capture file is loaded. (Bug 11989)
- Wireshark 2.0.1 crash on start. (Bug 11992)
- Wi-Fi 4-way handshake 4/4 is displayed as 2/4. (Bug 11994)
- ACN: acn.dmx.data has incorrect type. (Bug 11999)
- editcap packet comment won’t add multiple comments. (Bug 12007)
- DICOM Sequences no longer able to be expanded. (Bug 12011)
- Wrong TCP stream when port numbers are reused. (Bug 12022)
- SSL decryption fails in presence of a Client certificate. (Bug 12042)
- LUA: TVBs backing a data source is freed too early. (Bug 12050)
- PIM: pim.group filter have the same name for IPv4 and IPv6. (Bug 12061)
- Failed to parse M3AP IE (TNL information). (Bug 12070)
- Wrong interpretation of Instance ID value in OSPFv3 packet. (Bug 12072)
- MP2T Dissector does parse RTP properly in 2.0.1. (Bug 12099)
- editcap does not adjust time for frames with absolute timestamp 0 < t < 1 secs. (Bug 12116)
- Guard Interval is not consistent between Radiotap & wlan_radio. (Bug 12123)
- Calling dumpcap -i- results in access violation. (Bug 12143)
- Qt: Friendly Name and Interface Name columns should not be editable. (Bug 12146)
- PPTP GRE call ID not always decoded. (Bug 12149)
- Interface list does not show device description anymore. (Bug 12156)
- Find Packet does not highlight the matching tree item or packet bytes. (Bug 12157)
- "total block length … is too large" error when opening pcapng file with multiple SHB sections. (Bug 12167)
- http.request.full_uri is malformed if an HTTP Proxy is used. (Bug 12176)
- SNMP dissector fails at msgSecurityParameters with long length encoding. (Bug 12181)
- Windows installers and PortableApps® packages are now dual signed using SHA-1 and SHA-256 in order to comply with Microsoft Authenticode policy. Windows 7 and Windows Server 2008 R2 users should ensure that update 3123479 is installed. Windows Vista and Windows Server 2008 users should ensure that hotfix 2763674 is installed.
Updated Protocol Support:
- 6LoWPAN, ACN, ASN.1 BER, BATADV, DICOM, DNP3, DOCSIS INT-RNG-REQ, E100, EIGRP, GSM A DTAP, GSM SMS, GTP, HiQnet, HTTP, HTTP/2, IEEE 802.11, IKEv2, InfiniBand, IPv4, IPv6, LBMC, LLRP, M3AP, MAC LTE, MP2T, MPLS, NFS, NS Trace, OSPF, PIM, PPTP, RLC LTE, RoHC, RPC, RSL, SNMP, SPICE, SSL, TCP, TRILL, VXLAN, WaveAgent, and X.509AF
New and Updated Capture File Support:
- 3GPP TS 32.423 Trace, iSeries, Ixia IxVeriWave, pcap, and pcapng
更新時間:2016-01-01
更新細節:
What's new in this version:
- Zooming out (Ctrl+-) too far crashes Wireshark. ([52]Bug 8854)
- IPv6 Mobility Header Link-Layer Address Mobility Option is parsed incorrectly. ([53]Bug 10627)
- About -> Plugins should be a scrollable. ([54]Bug 11427)
- Profile change leaves prior profile residue. ([55]Bug 11493)
- Wireshark crashes when using the VoIP player. ([56]Bug 11596)
- Incorrect presentation of Ascend-Data-Filter (RADIUS attribute 242). ([57]Bug 11630)
- Not possible to stop a capture with invalid filter. ([58]Bug 11667)
- "No interface selected" when having a valid capture filter. ([59]Bug 11671)
- Malformed packet with IPv6 mobility header. ([60]Bug 11728)
- Wireshark crashes dissecting Profinet NRT (DCE-RPC) packet. ([61]Bug 11730)
- All fields in the packet detail pane of a "new packet" window are expanded by default. ([62]Bug 11731)
- Malformed packets with SET_CUR in the USBVIDEO (UVC) decoding. ([63]Bug 11736)
- Display filters arranges columns incorrectly. ([64]Bug 11737)
- Scrolling and navigating using the trackpad on Mac OS X could be much better. ([65]Bug 11738)
- Lua Proto() does not validate arguments. ([66]Bug 11739)
- Pointers to deallocated memory when redissecting. ([67]Bug 11740)
- Suggestion for re-phrasing the TCP Window Full message. ([68]Bug 11741)
- Can't parse MPEG-2 Transport Streams generated by the Logik L26DIGB21 TV. ([69]Bug 11749)
- Qt UI on Windows crashes when changing to next capture file. ([70]Bug 11756)
- First displayed frame not updated when changing profile. ([71]Bug 11757)
- LDAP decode shows invalid number of results for searchResEntry packets. ([72]Bug 11761)
- Crash when escape to Follow TCP -> Save. ([73]Bug 11763)
- USBPcap prevents mouse and keyboard from working. ([74]Bug 11766)
- Y-axis in RTP graph is in microseconds. ([75]Bug 11784)
- "Delta time displayed" column in Wireshark doesn't work well, but Wireshark-gtk does. ([76]Bug 11786)
- UDP 12001 SNA Data no longer shown in EBCDIC. ([77]Bug 11787)
- Wireshark Portable is not starting (no messages at all). ([78]Bug 11800)
- IPv6 RPL Routing Header with length of 8 bytes still reads an address. ([79]Bug 11803)
- g_utf8_validate assertion when reassembling GSM SMS messages encoded in UCS2. ([80]Bug 11809)
- Calling plugin_if_goto_frame when there is no file loaded causes a Protection Exception. ([81]Bug 11810)
- Qt UI SIGSEGV before main() in initializer for colors_. ([82]Bug 11833)
- Unable to add a directory to "GeoIP Database Paths". ([83]Bug 11842)
- C++ Run time error when filtering on Expert limit to display filter. ([84]Bug 11848)
- Widening the window doesn't correctly widen the rightmost column. ([85]Bug 11849)
- SSL V2 Client Hello no longer dissected in Wireshark 2.0. ([86]Bug 11851)
- PacketBB (RFC5444) dissector displays IPv4 addresses incorrectly. ([87]Bug 11852)
- SMTP over port 587 shows identical content for fields "Username" and "Password" when not decoding base-64-encoded authentication information. ([88]Bug 11853)
- Converting of EUI64 address to string does not take offset into account. ([89]Bug 11856)
- CIP segment dissection causes PDML assertion/failure. ([90]Bug 11863)
- In Import from Hex Dump, an attempt to enter the timestamp format manually crashes the application. ([91]Bug 11873)
- Follow Stream directional selector not readable. ([92]Bug 11887)
- Coloring rule custom colors not saved. ([93]Bug 11888)
- Total number of streams not correct in Follow TCP Stream dialog. ([94]Bug 11889)
- Command line switch -Y for display filter does not work. ([95]Bug 11891)
- Creating Debian package doesn't work. ([96]Bug 11893)
- Visual C++ Runtime Library Error "The application has requested the Runtime to terminate it in an unusual way." when you do not wait until Conversations is completely updated before applying "Limit to display filter". ([97]Bug 11900)
- dpkg-buildpackage relocation R_X86_64_PC32 against symbol. ([98]Bug 11901)
- Bits view in Packet Bytes pane is not persistent. ([99]Bug 11903)
- ICMP Timestamp days, hours, minutes, seconds is incorrect. ([100]Bug 11910)
- MPEG2TS NULL pkt: AFC: "Should be 0 for NULL packets" wrong. ([101]Bug 11921)
New and Updated Features:
- There are no new features in this release
New File Format Decoding Support:
- There are no new file formats in this release
New Protocol Support:
- There are no new protocols in this release
Updated Protocol Support:
- 6LoWPAN, ANSI A, ASN.1 BER, BT ATT, CIP, CLNP, DIAMETER, DNS, ENIP, ERF, GSM A, GSM SMS, HiSLIP, ICMP, IEEE 802.11, IEEE 802.11 Radio, IPMI, IPv4, IPv6, ISUP, L2TP, LDAP, Link (ethertype), MIP6, MP2T, MS-WSP, NBAP, NWP, PacketBB, PPI, QUIC, RADIUS, RSL, RSVP, S7COMM, SCSI, SCTP, SMTP, SSL, TCP, TDS, USB, VRT, and ZigBee ZCL
New and Updated Capture File Support:
- Ascend, ERF, MP2T, Sniffer, and VeriWave
New and Updated Capture Interfaces support:
- There are no new or updated capture interfaces supported in this release
更新時間:2016-01-01
更新細節:
What's new in this version:
- Zooming out (Ctrl+-) too far crashes Wireshark. ([52]Bug 8854)
- IPv6 Mobility Header Link-Layer Address Mobility Option is parsed incorrectly. ([53]Bug 10627)
- About -> Plugins should be a scrollable. ([54]Bug 11427)
- Profile change leaves prior profile residue. ([55]Bug 11493)
- Wireshark crashes when using the VoIP player. ([56]Bug 11596)
- Incorrect presentation of Ascend-Data-Filter (RADIUS attribute 242). ([57]Bug 11630)
- Not possible to stop a capture with invalid filter. ([58]Bug 11667)
- "No interface selected" when having a valid capture filter. ([59]Bug 11671)
- Malformed packet with IPv6 mobility header. ([60]Bug 11728)
- Wireshark crashes dissecting Profinet NRT (DCE-RPC) packet. ([61]Bug 11730)
- All fields in the packet detail pane of a "new packet" window are expanded by default. ([62]Bug 11731)
- Malformed packets with SET_CUR in the USBVIDEO (UVC) decoding. ([63]Bug 11736)
- Display filters arranges columns incorrectly. ([64]Bug 11737)
- Scrolling and navigating using the trackpad on Mac OS X could be much better. ([65]Bug 11738)
- Lua Proto() does not validate arguments. ([66]Bug 11739)
- Pointers to deallocated memory when redissecting. ([67]Bug 11740)
- Suggestion for re-phrasing the TCP Window Full message. ([68]Bug 11741)
- Can't parse MPEG-2 Transport Streams generated by the Logik L26DIGB21 TV. ([69]Bug 11749)
- Qt UI on Windows crashes when changing to next capture file. ([70]Bug 11756)
- First displayed frame not updated when changing profile. ([71]Bug 11757)
- LDAP decode shows invalid number of results for searchResEntry packets. ([72]Bug 11761)
- Crash when escape to Follow TCP -> Save. ([73]Bug 11763)
- USBPcap prevents mouse and keyboard from working. ([74]Bug 11766)
- Y-axis in RTP graph is in microseconds. ([75]Bug 11784)
- "Delta time displayed" column in Wireshark doesn't work well, but Wireshark-gtk does. ([76]Bug 11786)
- UDP 12001 SNA Data no longer shown in EBCDIC. ([77]Bug 11787)
- Wireshark Portable is not starting (no messages at all). ([78]Bug 11800)
- IPv6 RPL Routing Header with length of 8 bytes still reads an address. ([79]Bug 11803)
- g_utf8_validate assertion when reassembling GSM SMS messages encoded in UCS2. ([80]Bug 11809)
- Calling plugin_if_goto_frame when there is no file loaded causes a Protection Exception. ([81]Bug 11810)
- Qt UI SIGSEGV before main() in initializer for colors_. ([82]Bug 11833)
- Unable to add a directory to "GeoIP Database Paths". ([83]Bug 11842)
- C++ Run time error when filtering on Expert limit to display filter. ([84]Bug 11848)
- Widening the window doesn't correctly widen the rightmost column. ([85]Bug 11849)
- SSL V2 Client Hello no longer dissected in Wireshark 2.0. ([86]Bug 11851)
- PacketBB (RFC5444) dissector displays IPv4 addresses incorrectly. ([87]Bug 11852)
- SMTP over port 587 shows identical content for fields "Username" and "Password" when not decoding base-64-encoded authentication information. ([88]Bug 11853)
- Converting of EUI64 address to string does not take offset into account. ([89]Bug 11856)
- CIP segment dissection causes PDML assertion/failure. ([90]Bug 11863)
- In Import from Hex Dump, an attempt to enter the timestamp format manually crashes the application. ([91]Bug 11873)
- Follow Stream directional selector not readable. ([92]Bug 11887)
- Coloring rule custom colors not saved. ([93]Bug 11888)
- Total number of streams not correct in Follow TCP Stream dialog. ([94]Bug 11889)
- Command line switch -Y for display filter does not work. ([95]Bug 11891)
- Creating Debian package doesn't work. ([96]Bug 11893)
- Visual C++ Runtime Library Error "The application has requested the Runtime to terminate it in an unusual way." when you do not wait until Conversations is completely updated before applying "Limit to display filter". ([97]Bug 11900)
- dpkg-buildpackage relocation R_X86_64_PC32 against symbol. ([98]Bug 11901)
- Bits view in Packet Bytes pane is not persistent. ([99]Bug 11903)
- ICMP Timestamp days, hours, minutes, seconds is incorrect. ([100]Bug 11910)
- MPEG2TS NULL pkt: AFC: "Should be 0 for NULL packets" wrong. ([101]Bug 11921)
New and Updated Features:
- There are no new features in this release
New File Format Decoding Support:
- There are no new file formats in this release
New Protocol Support:
- There are no new protocols in this release
Updated Protocol Support:
- 6LoWPAN, ANSI A, ASN.1 BER, BT ATT, CIP, CLNP, DIAMETER, DNS, ENIP, ERF, GSM A, GSM SMS, HiSLIP, ICMP, IEEE 802.11, IEEE 802.11 Radio, IPMI, IPv4, IPv6, ISUP, L2TP, LDAP, Link (ethertype), MIP6, MP2T, MS-WSP, NBAP, NWP, PacketBB, PPI, QUIC, RADIUS, RSL, RSVP, S7COMM, SCSI, SCTP, SMTP, SSL, TCP, TDS, USB, VRT, and ZigBee ZCL
New and Updated Capture File Support:
- Ascend, ERF, MP2T, Sniffer, and VeriWave
New and Updated Capture Interfaces support:
- There are no new or updated capture interfaces supported in this release
更新時間:2015-11-19
更新細節:
What's new in this version:
WHAT'S NEW:
- Wireshark 2.0 features a completely new user interface which should provide a smoother, faster user experience. The new interface should be familiar to current users of Wireshark but provide a faster workflow for many tasks
- The Windows installer provides the option of installing either the new interface (“Wirehsark”) or the old interface (“Wireshark Legacy”). Both are installed by default. Note that the legacy interface will be removed in Wireshark 2.2
- The OS X installer only provides the new interface. If you need the old interface you can install it via Homebrew or MacPorts
- Wireshark’s Debian- and RPM-based package definitions provide the new interface in the “wireshark-qt” package and the old interface in the “wireshark-gtk” package. It is hoped that downstream distributions will follow this convention
New and Updated Features:
The following features are new (or have been significantly updated) since version 2.0.0rc3:
- An RTP player crash has been fixed
- Flow graph issues have been fixed. Bug Bug 11710
- A Follow Stream dialog crash has been fixed. Bug Bug 11711
- An extcap crash has been fixed
- A file merge crash has been fixed. Bug Bug 11718
- A handle leak crash has been fixed. Bug Bug 11702
- Several other crashes and usability issues have been fixed
The following features are new (or have been significantly updated) since version 2.0.0rc2:
- Column editing now works correctly. Bug Bug 11433
- Renaming profiles has been fixed. Bug Bug 11658
- “File”→Merge no longer crashes on Windows. Bug Bug 11684
- Icons in the main toolbar obey magnification settings on Windows. Bug Bug 11675
- The Windows installer does a better job of detecting WinPcap. Bug Bug 10867
- The main window no longer appears off-screen on Windows. Bug Bug 11568
The following features are new (or have been significantly updated) since version 2.0.0rc1:
- For new installations on UN*X, the directory for user preferences is $HOME/.config/wireshark rather than $HOME/.wireshark. If that directory is absent, preferences will still be found and stored under $HOME/.wireshark
Qt port:
- The SIP Statistics dialog has been added
- You can now create filter expressions from the display filter toolbar
- Bugs in the UAT preferences dialog has been fixed
- Several dissector and Qt UI crash bugs have been fixed
- Problems with the OS X application bundle have been fixed
The following features are new (or have been significantly updated) since version 1.99.9:
Qt port:
- The LTE RLC Graph dialog has been added
- The LTE MAC Statistics dialog has been added
- The LTE RLC Statistics dialog has been added
- The IAX2 Analysis dialog has been added
- The Conversation Hash Tables dialog has been added
- The Dissector Tables dialog has been added
- The Supported Protocols dialog has been added
- You can now zoom the I/O and TCP Stream graph X and Y axes independently
- The RTP Player dialog has been added
- Several memory leaks have been fixed
The following features are new (or have been significantly updated) since version 1.99.8:
Qt port:
- The MTP3 statistics and summary dialogs have been added
- The WAP-WSP statistics dialog has been added
- The UDP multicast statistics dialog has been added
- The WLAN statistics dialog has been added
- The display filter macros dialog has been added
- The capture file properties dialog now includes packet comments
- Many more statistics dialogs can be opened from the command line via -z ...
- Most dialogs now have a cancellable progress bar
- Many packet list and packet detail context menus items have been added
- Lua plugins can be reloaded from the Analyze menu
- Many bug fixes and improvements
The following features are new (or have been significantly updated) since version 1.99.7:
Qt port:
- The Enabled Protocols dialog has been added
- Many statistics dialogs have been added, including Service response time, DHCP/BOOTP, and ANSI
- The RTP Analysis dialog has been added
- Lua dialog support has been added
- You can now manually resolve addresses
- The Resolved Addresses dialog has been added
- The packet list scrollbar now has a minimap
- The capture interfaces dialog has been updated
- You can now colorize conversations
- Welcome screen behavior has been improved
- Plugin support has been improved
- Many dialogs should now more correctly minimize and maximize
- The reload button has been added back to the toolbar
- The "Decode As" dialog no longer saves decoding behavior
- You can now stop loading large capture files
- The Bluetooth HCI Summary has been added
The following features are new (or have been significantly updated) since version 1.99.6:
Qt port:
- The Bluetooth Devices dialog has been added
- The wireless toolbar has been added
- Opening files via drag and drop is now supported
- The Capture Filter and Display Filter dialogs have been added
- The Display Filter Expression dialog has been added
- Conversation Filter menu items have been added
- You can change protocol preferences by right clicking on the packet list and details
The following features are new (or have been significantly updated) since version 1.99.4 and 1.99.5:
Qt port:
- Capture restarts are now supported
- Menu items for plugins are now supported
- Extcap interfaces are now supporte
- The Expert Information dialog has been added
- Display and capture filter completion is now supported
- Many bugs have been fixed
- Translations have been updated
The following features are new (or have been significantly updated) since version 1.99.3:
Qt port:
- Several interface bugs have been fixed
- Translations have been updated
The following features are new (or have been significantly updated) since version 1.99.2:
Qt port:
- Several bugs have been fixed
- You can now open a packet in a new window
- The Bluetooth ATT Server Attributes dialog has been added
- The Coloring Rules dialog has been added
- Many translations have been updated. Chinese, Italian and Polish translations are complete
- General user interface and usability improvements
- Automatic scrolling during capture now works
- The related packet indicator has been updated
The following features are new (or have been significantly updated) since version 1.99.1:
Qt port:
- The welcome screen layout has been updated
- The Preferences dialog no longer crashes on Windows
- The packet list header menu has been added
- Statistics tree plugins are now supported
- The window icon is now displayed properly in the Windows taskbar
- A packet list an byte view selection bug has been fixed (Bug 10896)
- The RTP Streams dialog has been added
- The Protocol Hierarchy Statistics dialog has been added
The following features are new (or have been significantly updated) since version 1.99.0:
Qt port:
- You can now show and hide toolbars and major widgets using the View menu
- You can now set the time display format and precision
- The byte view widget is much faster, particularly when selecting large reassembled packets
- The byte view is explorable. Hovering over it highlights the corresponding field and shows a description in the status bar
- An Italian translation has been added
- The Summary dialog has been updated and renamed to Capture File Properties
- The VoIP Calls and SIP Flows dialogs have been added
- Support for HiDPI / Retina displays has been improved in the official packages
- DNS stats: + A new stats tree has been added to the Statistics menu. Now it is possible to collect stats such as qtype/qclass distribution, number of resource record per response section, and stats data (min, max, avg) for values such as query name length or DNS payload
- HPFEEDS stats: + A new stats tree has been added to the statistics menu. Now it is possible to collect stats per channel (messages count and payload size), and opcode distribution
- HTTP2 stats: + A new stats tree has been added to the statistics menu. Now it is possible to collect stats (type distribution)
The following features are new (or have been significantly updated) since version 1.12.0:
- The I/O Graph in the Gtk+ UI now supports an unlimited number of data points (up from 100k)
- TShark now resets its state when changing files in ring-buffer mode
- Expert Info severities can now be configured
- Wireshark now supports external capture interfaces. External capture interfaces can be anything from a tcpdump-over-ssh pipe to a program that captures from proprietary or non-standard hardware. This functionality is not available in the Qt UI yet
Qt port:
- The Qt UI is now the default (program name is wireshark)
- A Polish translation has been added
- The Interfaces dialog has been added
- The interface list is now updated when interfaces appear or disappear
- The Conversations and Endpoints dialogs have been added
- A Japanese translation has been added
- It is now possible to manage remote capture interfaces
- Windows: taskbar progress support has been added
- Most toolbar actions are in place and work
- More command line options are now supported
New File Format Decoding Support:
- Wireshark is able to display the format of some types of files (rather than displaying the contents of those files). This is useful when you’re curious about, or debugging, a file and its format. To open a capture file (such as PCAP) in this mode specify "MIME Files Format" as the file’s format in the Open File dialog
New files that Wireshark can open in this mode include:
BTSNOOP, PCAP, and PCAPNG
New Protocol Support:
- Aeron, AllJoyn Reliable Datagram Protocol, Android Debug Bridge, Android Debug Bridge Service, Android Logcat text, Apache Tribes Heartbeat, APT-X Codec, B.A.T.M.A.N. GW, B.A.T.M.A.N. Vis, BGP Monitoring Prototol (BMP), Bluetooth Broadcom HCI, Bluetooth GATT Attributes (many), Bluetooth OBEX Applications (many), BSSAP2, C15 Call History Protocol (C15ch) and others, Celerra VNX, Ceph, Chargen, Classical IP, Concise Binary Object Representation (CBOR) (RFC 7049), Corosync Totem Single Ring Protocol, Corosync Totemnet, Couchbase, CP “Cooper” 2179, CSN.1, dCache, DJI UAV Drone Control Protocol, Dynamic Source Routing (RFC 4728), Elasticsearch, ETSI Card Application Toolkit - Transport Protocol, eXpressive Internet Protocol (XIP), GDB Remote Serial Protocol, Generic Network Virtualization Encapsulation (Geneve), Geospatial and Imagery Access Service (GIAS), Gias Dissector Using GIOP API, GPRS Tunneling Protocol Prim, GVSP GigE Vision ™ Streaming Protocol, H.225 RAS, Harman HiQnet, HCrt, Hotline Command-Response Transaction Protocol, IEEE 802.11 radio information, IP Detail Record (IPDR), IPMI Trace, iSER, KNXnetIP, Link Aggregation Control Protocol, Link Aggregation Marker Protocol, Link Layer Topology Discovery, Link-local Multicast Name Resolution, LISP TCP Control Message, Locator/ID Separation Protocol (Reliable Transport), MACsec Key Agreement - EAPoL-MKA, MCPE (Minecraft Pocket Edition), Message Queuing Telemetry Transport For Sensor Networks (MQTT-SN), Minecraft Pocket Edition, MQ Telemetry Transport Protocol for Sensor Networks, Multicast Domain Name Service (mDNS), Neighborhood Watch Protocol (NWP), Network File System over Remote Direct Memory Access (NFSoRDMA), OAMPDU, OCFS2, OptoMMP, Organization Specific Slow Protocol (OSSP), Packet Cable Lawful Intercept (8 byte CCCID), Packet Cable Lawful Intercept (timestamp), Packet Cable Lawful Intercept (timestamp case ID), PacketCable MTA FQDN, Performance Co-Pilot Proxy, QNEX6 (QNET), RakNet games library, Remote Shared Virtual Disk (RSVD), Riemann, RPC over RDMA (RPCoRDMA), S7 Communication, Secure Socket Tunnel Protocol (SSTP), Shared Memory Communications - RDMA (SMCR), Stateless Transport Tunneling, Sysdig system call events, TCP based Robot Operating System protocol (TCPROS), Thrift, Time Division Multiplexing over Packet Network (TDMoP), Video Services over IP (VSIP), Windows Search Protocol (MS-WSP), XIP Serval, ZigBee ZCL (many), and ZVT Kassenschnittstelle
Updated Protocol Support:
- Too many protocols have been updated to list here
New and Updated Capture File Support:
- 3GPP TS 32.423 Trace, Android Logcat text files, Colasoft Capsa files, Netscaler 3.5, and Symbian OS BTSNOOP File Format
- Additionally, Wireshark now supports nanosecond timestamp resolution in PCAP-NG files
New and Updated Capture Interfaces support:
- Androiddump support now provides interfaces to capture (Logcat, Bluetooth and WiFi) from connected Android devices
Major API Changes:
The libwireshark API has undergone some major changes:
- The emem framework (including all ep_ and se_ memory allocation routines) has been completely removed in favour of wmem which is now fully mature
- The (long-since-broken) Python bindings support has been removed. If you want to write dissectors in something other than C, use Lua
- Plugins can now create GUI menu items
- Heuristic dissectors can now be globally enabled/disabled so heur_dissector_add() has a few more parameters to make that possible
- proto_tree_add_text has been removed
- tvb_length() has been removed in favor of tvb_reported_length() and tvb_captured_length()
- The API for ONC RPC-based dissectors has changed significantly: the procedure dissectors no longer take an offset, void-argument procedures now need to be declared with a function (use dissect_rpc_void()), and rpc_init_prog() now handles procedure registration too (it takes additional arguments to handle this; rpc_init_proc_table() was removed)
更新時間:2015-11-19
更新細節:
What's new in this version:
WHAT'S NEW:
- Wireshark 2.0 features a completely new user interface which should provide a smoother, faster user experience. The new interface should be familiar to current users of Wireshark but provide a faster workflow for many tasks
- The Windows installer provides the option of installing either the new interface (“Wirehsark”) or the old interface (“Wireshark Legacy”). Both are installed by default. Note that the legacy interface will be removed in Wireshark 2.2
- The OS X installer only provides the new interface. If you need the old interface you can install it via Homebrew or MacPorts
- Wireshark’s Debian- and RPM-based package definitions provide the new interface in the “wireshark-qt” package and the old interface in the “wireshark-gtk” package. It is hoped that downstream distributions will follow this convention
New and Updated Features:
The following features are new (or have been significantly updated) since version 2.0.0rc3:
- An RTP player crash has been fixed
- Flow graph issues have been fixed. Bug Bug 11710
- A Follow Stream dialog crash has been fixed. Bug Bug 11711
- An extcap crash has been fixed
- A file merge crash has been fixed. Bug Bug 11718
- A handle leak crash has been fixed. Bug Bug 11702
- Several other crashes and usability issues have been fixed
The following features are new (or have been significantly updated) since version 2.0.0rc2:
- Column editing now works correctly. Bug Bug 11433
- Renaming profiles has been fixed. Bug Bug 11658
- “File”→Merge no longer crashes on Windows. Bug Bug 11684
- Icons in the main toolbar obey magnification settings on Windows. Bug Bug 11675
- The Windows installer does a better job of detecting WinPcap. Bug Bug 10867
- The main window no longer appears off-screen on Windows. Bug Bug 11568
The following features are new (or have been significantly updated) since version 2.0.0rc1:
- For new installations on UN*X, the directory for user preferences is $HOME/.config/wireshark rather than $HOME/.wireshark. If that directory is absent, preferences will still be found and stored under $HOME/.wireshark
Qt port:
- The SIP Statistics dialog has been added
- You can now create filter expressions from the display filter toolbar
- Bugs in the UAT preferences dialog has been fixed
- Several dissector and Qt UI crash bugs have been fixed
- Problems with the OS X application bundle have been fixed
The following features are new (or have been significantly updated) since version 1.99.9:
Qt port:
- The LTE RLC Graph dialog has been added
- The LTE MAC Statistics dialog has been added
- The LTE RLC Statistics dialog has been added
- The IAX2 Analysis dialog has been added
- The Conversation Hash Tables dialog has been added
- The Dissector Tables dialog has been added
- The Supported Protocols dialog has been added
- You can now zoom the I/O and TCP Stream graph X and Y axes independently
- The RTP Player dialog has been added
- Several memory leaks have been fixed
The following features are new (or have been significantly updated) since version 1.99.8:
Qt port:
- The MTP3 statistics and summary dialogs have been added
- The WAP-WSP statistics dialog has been added
- The UDP multicast statistics dialog has been added
- The WLAN statistics dialog has been added
- The display filter macros dialog has been added
- The capture file properties dialog now includes packet comments
- Many more statistics dialogs can be opened from the command line via -z ...
- Most dialogs now have a cancellable progress bar
- Many packet list and packet detail context menus items have been added
- Lua plugins can be reloaded from the Analyze menu
- Many bug fixes and improvements
The following features are new (or have been significantly updated) since version 1.99.7:
Qt port:
- The Enabled Protocols dialog has been added
- Many statistics dialogs have been added, including Service response time, DHCP/BOOTP, and ANSI
- The RTP Analysis dialog has been added
- Lua dialog support has been added
- You can now manually resolve addresses
- The Resolved Addresses dialog has been added
- The packet list scrollbar now has a minimap
- The capture interfaces dialog has been updated
- You can now colorize conversations
- Welcome screen behavior has been improved
- Plugin support has been improved
- Many dialogs should now more correctly minimize and maximize
- The reload button has been added back to the toolbar
- The "Decode As" dialog no longer saves decoding behavior
- You can now stop loading large capture files
- The Bluetooth HCI Summary has been added
The following features are new (or have been significantly updated) since version 1.99.6:
Qt port:
- The Bluetooth Devices dialog has been added
- The wireless toolbar has been added
- Opening files via drag and drop is now supported
- The Capture Filter and Display Filter dialogs have been added
- The Display Filter Expression dialog has been added
- Conversation Filter menu items have been added
- You can change protocol preferences by right clicking on the packet list and details
The following features are new (or have been significantly updated) since version 1.99.4 and 1.99.5:
Qt port:
- Capture restarts are now supported
- Menu items for plugins are now supported
- Extcap interfaces are now supporte
- The Expert Information dialog has been added
- Display and capture filter completion is now supported
- Many bugs have been fixed
- Translations have been updated
The following features are new (or have been significantly updated) since version 1.99.3:
Qt port:
- Several interface bugs have been fixed
- Translations have been updated
The following features are new (or have been significantly updated) since version 1.99.2:
Qt port:
- Several bugs have been fixed
- You can now open a packet in a new window
- The Bluetooth ATT Server Attributes dialog has been added
- The Coloring Rules dialog has been added
- Many translations have been updated. Chinese, Italian and Polish translations are complete
- General user interface and usability improvements
- Automatic scrolling during capture now works
- The related packet indicator has been updated
The following features are new (or have been significantly updated) since version 1.99.1:
Qt port:
- The welcome screen layout has been updated
- The Preferences dialog no longer crashes on Windows
- The packet list header menu has been added
- Statistics tree plugins are now supported
- The window icon is now displayed properly in the Windows taskbar
- A packet list an byte view selection bug has been fixed (Bug 10896)
- The RTP Streams dialog has been added
- The Protocol Hierarchy Statistics dialog has been added
The following features are new (or have been significantly updated) since version 1.99.0:
Qt port:
- You can now show and hide toolbars and major widgets using the View menu
- You can now set the time display format and precision
- The byte view widget is much faster, particularly when selecting large reassembled packets
- The byte view is explorable. Hovering over it highlights the corresponding field and shows a description in the status bar
- An Italian translation has been added
- The Summary dialog has been updated and renamed to Capture File Properties
- The VoIP Calls and SIP Flows dialogs have been added
- Support for HiDPI / Retina displays has been improved in the official packages
- DNS stats: + A new stats tree has been added to the Statistics menu. Now it is possible to collect stats such as qtype/qclass distribution, number of resource record per response section, and stats data (min, max, avg) for values such as query name length or DNS payload
- HPFEEDS stats: + A new stats tree has been added to the statistics menu. Now it is possible to collect stats per channel (messages count and payload size), and opcode distribution
- HTTP2 stats: + A new stats tree has been added to the statistics menu. Now it is possible to collect stats (type distribution)
The following features are new (or have been significantly updated) since version 1.12.0:
- The I/O Graph in the Gtk+ UI now supports an unlimited number of data points (up from 100k)
- TShark now resets its state when changing files in ring-buffer mode
- Expert Info severities can now be configured
- Wireshark now supports external capture interfaces. External capture interfaces can be anything from a tcpdump-over-ssh pipe to a program that captures from proprietary or non-standard hardware. This functionality is not available in the Qt UI yet
Qt port:
- The Qt UI is now the default (program name is wireshark)
- A Polish translation has been added
- The Interfaces dialog has been added
- The interface list is now updated when interfaces appear or disappear
- The Conversations and Endpoints dialogs have been added
- A Japanese translation has been added
- It is now possible to manage remote capture interfaces
- Windows: taskbar progress support has been added
- Most toolbar actions are in place and work
- More command line options are now supported
New File Format Decoding Support:
- Wireshark is able to display the format of some types of files (rather than displaying the contents of those files). This is useful when you’re curious about, or debugging, a file and its format. To open a capture file (such as PCAP) in this mode specify "MIME Files Format" as the file’s format in the Open File dialog
New files that Wireshark can open in this mode include:
BTSNOOP, PCAP, and PCAPNG
New Protocol Support:
- Aeron, AllJoyn Reliable Datagram Protocol, Android Debug Bridge, Android Debug Bridge Service, Android Logcat text, Apache Tribes Heartbeat, APT-X Codec, B.A.T.M.A.N. GW, B.A.T.M.A.N. Vis, BGP Monitoring Prototol (BMP), Bluetooth Broadcom HCI, Bluetooth GATT Attributes (many), Bluetooth OBEX Applications (many), BSSAP2, C15 Call History Protocol (C15ch) and others, Celerra VNX, Ceph, Chargen, Classical IP, Concise Binary Object Representation (CBOR) (RFC 7049), Corosync Totem Single Ring Protocol, Corosync Totemnet, Couchbase, CP “Cooper” 2179, CSN.1, dCache, DJI UAV Drone Control Protocol, Dynamic Source Routing (RFC 4728), Elasticsearch, ETSI Card Application Toolkit - Transport Protocol, eXpressive Internet Protocol (XIP), GDB Remote Serial Protocol, Generic Network Virtualization Encapsulation (Geneve), Geospatial and Imagery Access Service (GIAS), Gias Dissector Using GIOP API, GPRS Tunneling Protocol Prim, GVSP GigE Vision ™ Streaming Protocol, H.225 RAS, Harman HiQnet, HCrt, Hotline Command-Response Transaction Protocol, IEEE 802.11 radio information, IP Detail Record (IPDR), IPMI Trace, iSER, KNXnetIP, Link Aggregation Control Protocol, Link Aggregation Marker Protocol, Link Layer Topology Discovery, Link-local Multicast Name Resolution, LISP TCP Control Message, Locator/ID Separation Protocol (Reliable Transport), MACsec Key Agreement - EAPoL-MKA, MCPE (Minecraft Pocket Edition), Message Queuing Telemetry Transport For Sensor Networks (MQTT-SN), Minecraft Pocket Edition, MQ Telemetry Transport Protocol for Sensor Networks, Multicast Domain Name Service (mDNS), Neighborhood Watch Protocol (NWP), Network File System over Remote Direct Memory Access (NFSoRDMA), OAMPDU, OCFS2, OptoMMP, Organization Specific Slow Protocol (OSSP), Packet Cable Lawful Intercept (8 byte CCCID), Packet Cable Lawful Intercept (timestamp), Packet Cable Lawful Intercept (timestamp case ID), PacketCable MTA FQDN, Performance Co-Pilot Proxy, QNEX6 (QNET), RakNet games library, Remote Shared Virtual Disk (RSVD), Riemann, RPC over RDMA (RPCoRDMA), S7 Communication, Secure Socket Tunnel Protocol (SSTP), Shared Memory Communications - RDMA (SMCR), Stateless Transport Tunneling, Sysdig system call events, TCP based Robot Operating System protocol (TCPROS), Thrift, Time Division Multiplexing over Packet Network (TDMoP), Video Services over IP (VSIP), Windows Search Protocol (MS-WSP), XIP Serval, ZigBee ZCL (many), and ZVT Kassenschnittstelle
Updated Protocol Support:
- Too many protocols have been updated to list here
New and Updated Capture File Support:
- 3GPP TS 32.423 Trace, Android Logcat text files, Colasoft Capsa files, Netscaler 3.5, and Symbian OS BTSNOOP File Format
- Additionally, Wireshark now supports nanosecond timestamp resolution in PCAP-NG files
New and Updated Capture Interfaces support:
- Androiddump support now provides interfaces to capture (Logcat, Bluetooth and WiFi) from connected Android devices
Major API Changes:
The libwireshark API has undergone some major changes:
- The emem framework (including all ep_ and se_ memory allocation routines) has been completely removed in favour of wmem which is now fully mature
- The (long-since-broken) Python bindings support has been removed. If you want to write dissectors in something other than C, use Lua
- Plugins can now create GUI menu items
- Heuristic dissectors can now be globally enabled/disabled so heur_dissector_add() has a few more parameters to make that possible
- proto_tree_add_text has been removed
- tvb_length() has been removed in favor of tvb_reported_length() and tvb_captured_length()
- The API for ONC RPC-based dissectors has changed significantly: the procedure dissectors no longer take an offset, void-argument procedures now need to be declared with a function (use dissect_rpc_void()), and rpc_init_prog() now handles procedure registration too (it takes additional arguments to handle this; rpc_init_proc_table() was removed)
更新時間:2015-10-14
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- Pcapng file parser crash. Discovered by Dario Lombardo and Shannon Sabens.
The following bugs have been fixed:
- Last Address field for IPv6 RPL routing header is interpreted incorrectly.
- Comparing two capture files crashes Wireshark when navigating the results.
- 802.11 frame is not correctly dissected if it contains HT Control.
- GVCP bit-fields not updated.
- Tshark crash when specifying ssl.keys_list on CLI.
- pcapng: SPB capture length is incorrectly truncated if IDB snaplen = 0.
- pcapng: NRB IPv4 address is endian swapped but shouldn't be.
- pcapng: NRB with options causes file read failure.
- pcapng: ISB without if_drop option is shown as max value.
- UNISTIM dissector - Message length not included in offset for "Select Adjustable Rx Volume".
更新時間:2015-10-14
更新細節:
What's new in this version:
The following vulnerabilities have been fixed:
- Pcapng file parser crash. Discovered by Dario Lombardo and Shannon Sabens.
The following bugs have been fixed:
- Last Address field for IPv6 RPL routing header is interpreted incorrectly.
- Comparing two capture files crashes Wireshark when navigating the results.
- 802.11 frame is not correctly dissected if it contains HT Control.
- GVCP bit-fields not updated.
- Tshark crash when specifying ssl.keys_list on CLI.
- pcapng: SPB capture length is incorrectly truncated if IDB snaplen = 0.
- pcapng: NRB IPv4 address is endian swapped but shouldn't be.
- pcapng: NRB with options causes file read failure.
- pcapng: ISB without if_drop option is shown as max value.
- UNISTIM dissector - Message length not included in offset for "Select Adjustable Rx Volume".
更新時間:2015-08-13
更新細節:
What's new in this version:
BUG FIXES:
- wnpa-sec-2015-21
- Protocol tree crash. (Bug 11309)
- Memory manager crash. (Bug 11373)
- Dissector table crash. (Bug 11381)
- ZigBee crash. (Bug 11389)
- GSM RLC/MAC infinite loop. (Bug 11358)
- WaveAgent crash. (Bug 11358)
- OpenFlow infinite loop. (Bug 11358)
- Ptvcursor crash. (Bug 11358)
- WCCP crash. (Bug 11358)
The following bugs have been fixed:
- DCE RPC "Decode As" capability is missing. (Bug 10368)
- Mergecap turns nanosecond-resolution time stamps into microsecond-resolution time stamps. (Bug 11202)
- The Aruba ERM Type 1 Dissector inconsistent with Type 0 and Type 3. (Bug 11204)
- Parse CFM Type Test signal (TST) without CRC. (Bug 11286)
- Tshark: output format of rpc.xid changed from Hex to Integer. (Bug 11292)
- Not stop -a filecount . (Bug 11305)
- lldp.ieee.802_3.mdi_power_class display is wrong. (Bug 11330)
- Powerlink (EPL) SDO packages interpreted as frame dublication. (Bug 11341)
- Mysql dissector adds packet content to INFO column without scrubbing it. (Bug 11344)
- PIM null-register according to rfc4601 is incorrectly parsed. (Bug 11354)
- Wireshark Lua dissectors: both expand together. (Bug 11356)
- Link-type not retrieved for rpcap interfaces configured with authentication. (Bug 11366)
- SSL Decryption (RSA private key with p smaller than q) failing on the Windows 7 buildbot. (Bug 11372)
- [gtpv2]PCSCF ip in the Protocol configuration of update bearer request is not getting populated. (Bug 11378)
- wpan.src64 (and dst64) filter always gives "is not a valid EUI64 Address" error. (Bug 11380)
- Websphere MQ Work Information Header incorrectly showing "Reserved". (Bug 11384)
- DUP ACK Counter resetting after Window Update. (Bug 11397)
- CSV values missing when using tshark -2 option. (Bug 11401)
- Ethernet PAUSE frames are decoded incorrectly as PFC. (Bug 11403)
- SOCKS decoder giving strange values for seemingly normal SOCKS connection. (Bug 11417)
- 802.11ad decoding error. (Bug 11419)