Wireshark is the world's foremost network protocol analyzer, and is the de facto standard across many industries and educational institutions.
- Deep inspection of hundreds of protocols, with more being added all the time
- Live capture and offline analysis
- Standard three-pane packet browser
- Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
- Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility
- The most powerful display filters in the industry
- Rich VoIP analysis
- Read/write many different capture file formats
- Capture files compressed with gzip can be decompressed on the fly
- Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)
- Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2
- Coloring rules can be applied to the packet list for quick, intuitive analysis
- Output can be exported to XML, PostScript®, CSV, or plain text
# The following bugs have been fixed:
- Customized OUI is not recognized correctly during dissection.
- Properly decode CAPWAP Data Keep-Alives.
- Build failure with GTK 3.10 - GTK developers have gone insane.
- SIGSEGV/SIGABRT during free of TvbRange using a chained dissector in lua.
- MPLS dissector no longer registers itself in "ppp.protocol" table.
- Tshark doesn’t display the longer data fields (mbtcp).
- DMX-CHAN disector does not clear strbuf between rows.
- Dissector bug, protocol SDP: proto.c:4214: failed assertion "length >= 0".
- False error: capture file appears to be damaged or corrupt.
- SMPP field source_telematics_id field length different from spec.
- Lua: bitop library is missing in Lua 5.2.
- GTPv1-C / MM Context / Authentication quintuplet / RAND is not correct.
- Lua: ProtoField.new() is buggy.
- Lua: ProtoField.bool() VALUESTRING argument is not optional but was supposed to be.
- Problem with CAPWAP Wireshark Dissector.
- nas-eps dissector: CS Service notification dissection stops after Paging identity IE.
# New and Updated Features
- IPv4 checksum verfification is now disabled by default.
# Updated Protocol Support
- AppleTalk, CAPWAP, DMX-CHAN, DSI, DVB-CI, ESS, GTPv1, IEEE 802a, M3UA, Modbus/TCP, NAS-EPS, NFS, OpenSafety, SDP, and SMPP
# New and Updated Capture File Support
- libpcap, MPEG, and pcap-ng