Wireshark is the world's foremost network protocol analyzer, and is the de facto standard across many industries and educational institutions.
- Deep inspection of hundreds of protocols, with more being added all the time
- Live capture and offline analysis
- Standard three-pane packet browser
- Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
- Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility
- The most powerful display filters in the industry
- Rich VoIP analysis
- Read/write many different capture file formats
- Capture files compressed with gzip can be decompressed on the fly
- Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)
- Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2
- Coloring rules can be applied to the packet list for quick, intuitive analysis
- Output can be exported to XML, PostScript®, CSV, or plain text
The following vulnerabilities have been fixed:
MS-WSP dissector crash.
Steam IHS Discovery dissector memory leak.
CoAP dissector crash.
OpcUA dissector crash.
The following bugs have been fixed:
HTTP2 dissector decodes first SSL record only.
Undocumented sub-option for -N option in man page and tshark -N help.
Mishandling of Port Control Protocol option padding.
MGCP: parameter lines are case-insensitive.
Details of 2nd sub-VSA in bundled RADIUS VSA are incorrect.
Heuristic DPLAY dissector fails to recognize DPLAY packets.
gsm_rlcmac_dl dissector exception.
dfilter_buttons file under user-created profile.
Filter buttons disappear when using pre-2.6 profile.
PROFINET Information element AM_DeviceIdentification in Asset Management Info block is decoded wrongly.
Hw dest addr column shows incorrect address.
Windows dumpcap -i TCP@<ip-address> fails on pcapng stream.
Wildcard expansion doesn’t work on Windows 10 for command-line programs in cmd.exe or PowerShell.
SSL Reassembly Error New fragment past old data limits.