Wireshark

Wireshark 2.4.3 (64-bit)

Wireshark.org
開源軟體

Wireshark 1.12.6 (32-bit)

更新時間:2015-06-18
更新細節:

# Bug Fixes
- WCCP dissector crash.
- GSM DTAP dissector crash.
- Wireshark 1.12.1 crashes on startup on Mac OS X 10.10 (Yosemite).
- Wireshark does not display X.400 addresses correctly.
- Reproducible crash in "Edit column details" dialog.
- Subnet name resolution doesn’t always work.
- SIP MIME body containing ISUP does not decode properly.
- iSCSI: Read(10): shows incorrect "Data In" & "Response" frame number.
- tshark -z io,stat,1,SUM(ip.len) reports invalid stats, triggers ASAN buffer overrun.
- Port Control Protocol packet dissection decodes R bit incorrectly.
# Updated Protocol Support
- GSM DTAP, iSCSI, P1, PCP, SIP, and WCCP


版本下載:Wireshark 1.12.6 (32-bit)

Wireshark 1.99.6 (32-bit) Beta

更新時間:2015-05-29
更新細節:

- Capture restarts are now supported.
- Menu items for plugins are now supported.
- Extcap interfaces are now supported.
- The Expert Information dialog has been added.
- Display and capture filter completion is now supported.
- Many bugs have been fixed.
- Translations have been updated.


版本下載:Wireshark 1.99.6 (32-bit) Beta

Wireshark 1.12.5 (32-bit)

更新時間:2015-05-13
更新細節:

# Bugs fixed:
- Wireshark crashes if "Update list of packets in real time" is disabled and a display filter is applied while capturing.
- EAPOL 4-way handshake information wrong.
- RPC NULL calls incorrectly flagged as malformed.
- Wireshark relative ISN set incorrectly if raw ISN set to 0.
- Buffer overrun in encryption code.
- Crash when use Telephony / Voip calls.
- ICMP Parameter Problem message contains Length of original datagram is treated as the total IPv4 length.
- ICMP Redirect takes 4 bytes for IPv4 payload instead of 8.
- Missing field "tcp.pdu.size" in TCP stack.
- Sierra EM7345 marks MBIM packets as NCM.
- Possible infinite loop DoS in ForCES dissector.
- "Decode As…" crashes when a packet dialog is open.
- Interface Identifier incorrectly represented by Wireshark.
- "Follow UDP Stream" on mpeg packets crashes wireshark v.1.12.4 (works fine on v.1.10.13).
- Annoying popup when trying to capture on bonds.
- Request-response cross-reference in USB URB packets incorrect.
- Right clicking in Expert Infos to create a filter (duplicate IP) results in invalid filters.
- CanOpen dissector fails on frames with RTR and 0 length.
- Typo in secp521r1 curve wrongly identified as sect521r1.
- packet-zbee-zcl.h: IS_ANALOG_SUBTYPE doesn’t filter ENUM.
- Typo: "LTE Positioning Protocol" abbreviated as "LPP", not "LLP".
- Missing Makefile.nmake in ansi1/Kerberos directory.
- Can’t build tshark without the Qt packages installed unless --without-qt is specified.
# Updated Protocol Support
- AllJoyn, ASN.1 PER, ATM, CANopen, Diameter, ForCES, GSM RLC/MAC, GSMTAP, ICMP, IEC-60870-5-104, IEEE 802.11, IMF, IP, LBMC, LBMR, LDAP, LPP, MBIM, MEGACO, MP2T, PKCS-1, PPP IPv6CP, RPC, SPNEGO, SRVLOC, SSL, T.38, TCP, USB, WCP, WebSocket, X11, and ZigBee ZCL


版本下載:Wireshark 1.12.5 (32-bit)

Wireshark 1.99.5 (32-bit) Beta

更新時間:2015-03-20
更新細節:

No change log.


版本下載:Wireshark 1.99.5 (32-bit) Beta

Wireshark 1.99.3 (32-bit) Beta

更新時間:2015-03-06
更新細節:

No change log.


版本下載:Wireshark 1.99.3 (32-bit) Beta

Wireshark 1.12.4 (32-bit)

更新時間:2015-03-06
更新細節:

# Bugs fixed:
- RTP player crashes on decode of long call: BadAlloc (insufficient resources for operation)
- "Telephony→SCTP→Analyse This Association" crashes Wireshark on manufactured SCTP packet.
- IPv6 Mobility Header Link Layer Address is parsed incorrectly.
- DNS NXT RR is parsed incorrectly.
- IPv6 AUTH mobility option parses Mobility SPI and Authentication Data incorrectly.
- IPv6 Mobility Header Link-Layer Address Mobility Option is parsed incorrectly.
- HTTP chunked response includes data beyond the chunked response.
- DHCP Option 125 Suboption: (1) option-len always expects 1 but specification allows for more.
- Incorrect decoding of IPv4 Interface/Neighbor Address sub-TLVs in Extended IS Reachability TLV of IS-IS.
- Little-endian OS X Bluetooth PacketLogger files aren’t handled.
- X.509 certificate serial number incorrectly interpreted as negative number.
- Malformed Packet on rsync-version with length 2.
- ZigBee epoch time is incorrectly displayed in OTA cluster.
- BGP EVPN - Route Type 4 - "Invalid length of IP Address" - "Expert Info" shows a false error.
- Bad bytes read for extended rnc id value in GTP dissector.
- "ServiceChangeReasonStr" messages are not shown in txt generated by tshark.
- Clang ASAN : AddressSanitizer: global-buffer-overflow ANSI.
- MEGACO wrong decoding on media port.
- Wrong media format.
- BSSGP Status PDU decoding fault (missing Mandatory element (0x04) BVCI for proper packet).
- DNS LOC Precision missing units.
- Packets on OpenBSD loopback decoded as raw not null.
- Display Filter Macro unable to edit.
- IPv6 Local Mobility Anchor Address mobility option code is treated incorrectly.
- SNTP server list improperly formatted in DHCPv6 packet details.
- Juniper Packet Mirror dissector expects ipv6 flow label = 0.
- NS Trace (NetScaler Trace) file format is not able to export specified packets.
- The ATN-CPDLC dissector could crash.
- The WCP dissector could crash.
- The pcapng file parser could crash.
- The LLDP dissector could crash.
- The TNEF dissector could go into an infinite loop.
- The SCSI OSD dissector could go into an infinite loop.


版本下載:Wireshark 1.12.4 (32-bit)

Wireshark 1.99.2 (32-bit) Beta

更新時間:2015-02-05
更新細節:

No change log.


版本下載:Wireshark 1.99.2 (32-bit) Beta

Wireshark 1.12.3 (32-bit)

更新時間:2015-01-09
更新細節:

# The following vulnerabilities have been fixed.
* The WCCP dissector could crash.
* The LPP dissector could crash.
* The DEC DNA Routing Protocol dissector could crash.
* The SMTP dissector could crash.
* Wireshark could crash while decypting TLS/SSL sessions. Discovered by Noam Rathaus.
# The following bugs have been fixed:
* WebSocket dissector: empty payload causes DISSECTOR_ASSERT_NOT_REACHED.
* Wireshark crashes if Lua heuristic dissector returns true.
* Display MEP ID in decimal in OAM Y.1731 Synthetic Loss Message and Reply PDU.
* TCP Window Size incorrectly reported in Packet List.
* Status bar "creeps" to the left a few pixels every time Wireshark is opened.
* E-LMI Message type.
* SMTP decoder can dump binary data to terminal in TShark.
* PTPoE dissector gets confused by packets that include an FCS.
* IPv6 Vendor Specific Mobility Option includes the next mobility option type.
* Save PCAP to PCAPng with commentary fails.
* Display filter "frame contains bytes [2342]" causes a crash.
* Multipath TCP: checksum displayed when it’s not there.
* LTE APN-AMBR is decoded incorrectly.
* DNS NAPTR RR Replacement Length is incorrect.
* IPv6 Experimental mobility header data is interpreted as options.
* Dissector bug, protocol SPDY: tvbuff.c:610: failed assertion "tvb && tvb→initialized".
* BGP: Incorrect decoding AS numbers when mixed AS size.
* BGP update community - incorrect decoding.
* Setting a 6LoWPAN context generates a Wireshark crash.
* FC is not dissected (protocol UNKNOWN).
* Crash when displaying several times INFO column.
* Decoding of longitude value in LCSAP (3GPP TS 29.171) is incorrect.
* Crash when enabling FCoIB manual settings without filling address field.
* RSVP RECORD_ROUTE IPv4 Subobject Flags field incorrect decoding.
* Wireshark Lua engine can’t access protocol field type.
* Field Analysis of OpenFlow v1.4 OFPT_SET_ASYNC.
* Lua: getting fieldinfo.value for FT_NONE causes assert.
# Updated Protocol Support
* 6LoWPAN, ADwin, AllJoyn, Art-Net, Asterix, BGP, Bitcoin, Bluetooth OBEX, Bluetooth SDP, CFM, CIP, DCERPC PN-IO, DCERPC SPOOLSS, DEC DNA, DECT, DHCPv6, DNS, DTN, E-LMI, ENIP, Ethernet, Extreme, FCoIB, Fibre Channel, GED125, GTP, H.248, H.264, HiSLIP, IDRP, IEEE 802.11, IEEE P1722.1, Infiniband, IrDA, iSCSI, ISUP, LBMR, LCSAP, LPP, MAC LTE, MAUSB, MBIM, MIM, MIP, MIPv6, MP2T, MPEG-1, NAS EPS, NAT-PMP, NCP, NXP PN532, OpcUa, OpenFlow, PTP, RDM, RPKI-RTR, RSVP, RTnet, RTSP, SCTP, SMPP, SMTP, SPDY, Spice, TCP, WCCP, Wi-Fi P2P, and WiMAX
# New and Updated Capture File Support
* K12


版本下載:Wireshark 1.12.3 (32-bit)

Wireshark 1.99.1 (32-bit) Beta

更新時間:2014-12-11
更新細節:

- You can now show and hide toolbars and major widgets using the View menu.
- You can now set the time display format and precision.
- The byte view widget is much faster, particularly when selecting large reassembled packets.
- The byte view is explorable. Hovering over it highlights the corresponding field and shows a description in the status bar.
- An Italian translation has been added.
- The Summary dialog has been updated and renamed to Capture File Properties.
- The VoIP Calls and SIP Flows dialogs have been added.


版本下載:Wireshark 1.99.1 (32-bit) Beta

Wireshark 1.12.2 (32-bit)

更新時間:2014-11-13
更新細節:

# The following vulnerabilities have been fixed.
* SigComp UDVM buffer overflow.
* AMQP crash.
* NCP crashes.
* TN5250 infinite loops.
# The following bugs have been fixed:
* Wireshark determine packets of MMS protocol as a packets of T.125 protocol.
* 6LoWPAN Mesh headers not treated as encapsulating address.
* UCP dissector bug of operation 31 - PID 0639 not recognized.
* iSCSI dissector rejects PDUs with "expected data transfer length" > 16M.
* GTPv2: trigging_tree under Trace information has wrong length.
* openflow_v1 OFPT_FEATURES_REPLY parsed incorrectly.
* Capture files from a remote virtual interface on MacOS X 10.9.5 aren’t dissected correctly.
* Problem specifying protocol name for filtering.
* LLDP TIA Network Policy Unknown Policy Flag Decode is not correct.
* Decryption of DCERPC with Kerberos encryption fails.
* Dissection of DECRPC NT sid28 shouldn’t show expert info if tree is null.
* Attempt to render an SMS-DELIVER-REPORT instead of an SMS-DELIVER.
* IPv6 Calipso option length is not used properly.
* The SPDY dissector couldn’t dissecting packet correctly.
* IPv6 QuickStart option Nonce is read incorrectly.
* IPv6 Mobility Option IPv6 Address/Prefix marks too many bytes for the address/prefix field.
* IPv6 Mobility Option Binding Authorization Data for FMIPv6 Authenticator field is read beyond the option data.
* IPv6 Mobility Option Mobile Node Link Layer Identifier Link-layer Identifier field is read beyond the option data.
* Wrong offset for hf_mq_id_icf1 in packet-mq.c.
* Malformed PTPoE announce packet.
* IPv6 Permanent Home Keygen Token mobility option includes too many bytes for the token field.
* IPv6 Redirect Mobility Option K and N bits are parsed incorrectly.
* IPv6 Care Of Test mobility option includes too many bytes for the Keygen Token field.
* IPv6 MESG-ID mobility option is parsed incorrectly.
* IPv6 AUTH mobility option parses Mobility SPI and Authentication Data incorrectly.
* IPv6 DNS-UPDATE-TYPE mobility option includes too many bytes for the MD identity field.
* IPv6 Local Mobility Anchor Address mobility option’s code and reserved fields are parsed as 2 bytes instead of 1.
* WCCP v.2.01 extended assignment data element parsed wrong.
* DNS ISDN RR Sub Address field is read one byte early.
* TShark crashes when running with PDML on a specific packet.
* DNS A6 Address Suffix field is parsed incorrectly.
* DNS response time: calculation incorrect.
* SMPP does not display properly the hour field in the Submit_sm Validity Period field.
* DNS Name Length for Zone RR on root is 6 and Label Count is 1.
* DNS WKS RR Protocol field is read as 4 bytes instead of 1.
* IPv6 Mobility Option Context Request reads an extra request.
# Updated Protocol Support
* 6LoWPAN, AMQP, ANSI IS-637-A, Bluetooth HCI, CoAP, DCERPC (all), DCERPC NT, DNS, GSM MAP, GTPv2, H.223, HPSW, HTTP2, IEEE 802.11, IPv6, iSCSI, Kerberos, LBT-RM, LLDP, MIH, Mobile IPv6, MQ, NCP, OpcUa, OpenFlow, PKTAP, PTPoE, SigComp, SMB2, SMPP, SPDY, Stanag 4607, T.125, UCP, USB CCID, and WCCP
# New and Updated Capture File Support
* Catapult DCT2000, HP-UX nettl, Ixia IxVeriWave, pcap, pcap-ng, RADCOM, and Sniffer (DOS)


版本下載:Wireshark 1.12.2 (32-bit)

Wireshark 1.99.0 (32-bit) Beta

更新時間:2014-10-09
更新細節:

No change log.


版本下載:Wireshark 1.99.0 (32-bit) Beta

Wireshark 1.12.1 (32-bit)

更新時間:2014-09-17
更新細節:

* The following vulnerabilities have been fixed.
- MEGACO dissector infinite loop.
- Netflow dissector crash.
- CUPS dissector crash.
- HIP dissector infinite loop.
- RTSP dissector crash.
- SES dissector crash.
- Sniffer file parser crash.
* The following bugs have been fixed:
- Wireshark can crash during remote capture (rpcap) configuration.
- 802.11 capture does not decrypt/decode DHCP response.
- Extra quotes around date fields (FT_ABSOLUTE_TIME) when using -E quote=d or s.
- No progress line in "VOIP RTP Player".
- MIPv6 Service Selection Identifier parse error.
- Probably wrong length check in proto_item_set_end.
- 802.11 BA sequence number decode is broken.
- wmem_alloc_array() "succeeds" (and clobbers memory) when requested to allocate 0xaaaaaaaa items of size 12.
- Different dissection results for same file.
- Mergecap wildcard breaks in version 1.12.0.
- Diameter TCP reassemble.
- TRILL NLPID 0xc0 unknown to Wireshark.
- BTLE advertising header flags (RxAdd/TxAdd) dissected incorrectly.
- Ethernet OAM (CFM) frames including TLV’s are wrongly decoded as malformed.
- BGP4: Wireshark skipped some potion of AS_PATH.
- MAC address name resolution is broken.
- Wrong decoding of RPKI RTR End of Data PDU.
- SSL/TLS dissector incorrectly interprets length for status_request_v2 hello extension.
- Misparsed NTP control assignments with empty values.
- 6LoWPAN multicast address decompression problems.
- Netflow v9 flowset not decoded if options template has zero-length scope section.
- GUI Hangs when Selecting Path to GeoIP Files.
- AX.25 dissector prints unprintable characters.
- 6LoWPAN context handling not working.
- SIP: When export to a CSV, Info is changed to differ.
- Typo in packet-netflow.c.
- Incorrect MPEG-TS decoding (OPCR field).
* Updated Protocol Support
- 6LoWPAN, A21, ACR122, Art-Net, AX.25, BGP, BTLE, CAPWAP, DIAMETER, DICOM, DVB-CI, Ethernet OAM, HIP, HiSLIP, HTTP2, IEEE 802.11, MAUSB, MEGACO, MIPv6, MP2T, Netflow, NTP, openSAFETY, OSI, RDM, RPKI RTR, RTSP, SES, SIP, TLS, and Token Ring MAC
* New and Updated Capture File Support
- DOS Sniffer, and NetScaler


版本下載:Wireshark 1.12.1 (32-bit)

Wireshark 1.12.0 (32-bit)

更新時間:2014-08-01
更新細節:

* The following bugs have been fixed:
- "On-the-wire" packet lengths are limited to 65535 bytes.
- "Follow TCP Stream" shows only the first HTTP request and response.
- Files with pcap-ng Simple Packet Blocks can’t be read.
- MPLS-over-PPP isn’t recognized.
* The following features are new or have been significantly updated since version 1.10:
- The Windows installer now uninstalls the previous version of Wireshark silently. You can still run the uninstaller manually beforehand if you wish to run it interactively.
- Expert information is now filterable when the new API is in use.
- The "Number" column shows related packets and protocol conversation spans (Qt only).
- When manipulating packets with editcap using the -C <choplen> and/or -s <snaplen> options, it is now possible to also adjust the original frame length using the -L option.
- You can now pass the -C <choplen> option to editcap multiple times, which allows you to chop bytes from the beginning of a packet as well as at the end of a packet in a single step.
- You can now specify an optional offset to the -C option for editcap, which allows you to start chopping from that offset instead of from the absolute packet beginning or end.
- "malformed" display filter has been renamed to "_ws.malformed". A handful of other filters have been given the "_ws." prefix to note they are Wireshark application specific filters and not dissector filters.
- The Kerberos dissector has been replaced with an auto generated one from ASN1 protocol description, changing a lot of filter names.
* Additionally the Windows installers have an extra component: a preview of the upcoming user interface for Wireshark 2.0.
* The following features are new (or have been significantly updated) since version 1.11.3:
- Transport name resolution is now disabled by default.
- Support has been added for all versions of the DCBx protocol.
- Cleanup of LLDP code, all dissected fields are now navigable.
* The following features are new (or have been significantly updated) since version 1.11.2:
- Qt port:
> The About dialog has been added
> The Capture Interfaces dialog has been added.
> The Decode As dialog has been added. It managed to swallow up the User Specified Decodes dialog as well.
> The Export PDU dialog has been added.
> Several SCTP dialogs have been added.
> The statistics tree (the backend for many Statistics and Telephony menu items) dialog has been added.
> The I/O Graph dialog has been added.
> French translation has updated.
* The following features are new (or have been significantly updated) since version 1.11.1:
- Mac OS X packaging has been improved.
* The following features are new (or have been significantly updated) since version 1.11.0:
- Dissector output may be encoded as UTF-8. This includes TShark output.
- Qt port:
> The Follow Stream dialog now supports packet and TCP stream selection.
> A Flow Graph (sequence diagram) dialog has been added.
> The main window now respects geometry preferences.
* Removed Dissectors
- The ASN1 plugin has been removed as it’s deemed obsolete.
- The GNM dissector has been removed as it was never used.
- The Kerberos hand made dissector has been replaced by one generated from ASN1 code.
* New Protocol Support
- 29West, 802.1AE Secure tag, A21, ACR122, ADB Client-Server, AllJoyn, Apple PKTAP, Aruba Instant AP, ASTERIX, ATN, Bencode, Bluetooth 3DS, Bluetooth HSP, Bluetooth Linux Monitor Transport, Bluetooth Low Energy, Bluetooth Low Energy RF Info, CARP, CFDP, Cisco MetaData, DCE/RPC MDSSVC, DeviceNet, ELF file format, Ethernet Local Management Interface (E-LMI), Ethernet Passive Optical Network (EPON), EXPORTED PDU, FINGER, HDMI, High-Speed LAN Instrument Protocol (HiSLIP), HTTP2, IDRP, IEEE 1722a, ILP, iWARP Direct Data Placement and Remote Direct Memory Access Protocol, Kafka, Kyoto Tycoon, Landis & Gyr Telegyr 8979, LBM, LBMC, LBMPDM, LBMPDM-TCP, LBMR, LBT-RM, LBT-RU, LBT-TCP, Lightweight Mesh (v1.1.1), Link16, Linux netlink, Linux netlink netfilter, Linux netlink sock diag, Linux rtnetlink (route netlink), Logcat, MBIM, Media Agnostic USB (MA USB), MiNT, MP4 / ISOBMFF file format, MQ Telemetry Transport Protocol, MS NLB (Rewrite), Novell PKIS certificate extensions, NXP PN532 HCI, Open Sound Control, OpenFlow, Pathport, PDC, Picture Transfer Protocol Over IP, PKTAP, Private Data Channel, QUIC (Quick UDP Internet Connections), SAE J1939, SEL RTAC (Real Time Automation Controller) EIA-232 Serial-Line Dissection, Sippy RTPproxy, SMB-Direct, SPDY, STANAG 4607, STANAG 5066 DTS, STANAG 5066 SIS, Tinkerforge, Ubertooth, UDT, URL Encoded Form Data, USB Communications and CDC Control, USB Device Firmware Upgrade, VP8, WHOIS, Wi-Fi Display, and ZigBee Green Power profile
* New and Updated Capture File Support
- Netscaler 2.6, STANAG 4607, and STANAG 5066 Data Transfer Sublayer
* Major API Changes
- A more flexible, modular memory manager (wmem) has been added. It was available experimentally in 1.10 but is now mature and has mostly replaced the old emem API (which is deprecated).
- A new API for expert information has been added, replacing the old one.
- The tvbuff API has been cleaned up: tvb_length has been renamed to tvb_captured_length for clarity, and tvb_get_string and tvb_get_stringz have been deprecated in favour of tvb_get_string_enc and tvb_get_stringz_enc.
- dissector_try_heuristic() signature has been changed to return heur_dtbl_entry_t to make it possible to save it and use it in subsequent calls to avoid the overhead of going trough the heuristics list.


版本下載:Wireshark 1.12.0 (32-bit)

Wireshark 1.12.0 (32-bit) RC3

更新時間:2014-07-23
更新細節:

# The following bugs have been fixed:
* "On-the-wire" packet lengths are limited to 65535 bytes.
* "Follow TCP Stream" shows only the first HTTP request and response.
* Files with pcap-ng Simple Packet Blocks can't be read.
* MPLS-over-PPP isn't recognized.


版本下載:Wireshark 1.12.0 (32-bit) RC3

Wireshark 1.12.0 (32-bit) RC2

更新時間:2014-06-16
更新細節:

No change log.


版本下載:Wireshark 1.12.0 (32-bit) RC2