Wireshark is the world's foremost network protocol analyzer, and is the de facto standard across many industries and educational institutions.
- Deep inspection of hundreds of protocols, with more being added all the time
- Live capture and offline analysis
- Standard three-pane packet browser
- Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
- Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility
- The most powerful display filters in the industry
- Rich VoIP analysis
- Read/write many different capture file formats
- Capture files compressed with gzip can be decompressed on the fly
- Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)
- Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2
- Coloring rules can be applied to the packet list for quick, intuitive analysis
- Output can be exported to XML, PostScript®, CSV, or plain text
# The following bugs have been fixed:
* User-Password - PAP decoding passwords longer than 16 bytes.
* The MSISDN is not seen correctly in GTP packet.
* Wireshark doesn't calculate the right IPv4 destination using source routing options when bad options precede them.
* BOOTP dissector issue with DHCP option 82 - suboption 9.
* MPLS dissector in 1.6.7 and 1.7.1 misdecodes some MPLS CW packets.
* ANSI MAP infinite loop.
* HCIEVT infinite loop.
* Wireshark doesn't decode NFSv4.1 operations.
* LTP infinite loop.
* Wrong values in DNS CERT RR.
* Megaco parser problem with LF in header.
* OPC UA bytestring node id decoding is wrong.
# Updated Protocol Support
* ANSI MAP, ASF, BACapp, Bluetooth HCI, DHCP, DIAMETER, DNS, GTP, IEEE 802.11, IEEE 802.3, IPv4, LTP, Megaco, MPLS, NFS, OPC UA, RADIUS
# New and Updated Capture File Support
* 5View, CSIDS, pcap, pcap-ng