- Wireshark 2.1.0 Release Notes
+Wireshark 2.5.1 Release Notes
- This is a semi-experimental release intended to test new features for
- Wireshark 2.2.
- __________________________________________________________________
+ This is a semi-experimental release intended to test new features
+ for Wireshark 2.6.
-What is Wireshark?
+ What is Wireshark?
- Wireshark is the world's most popular network protocol analyzer. It is
- used for troubleshooting, analysis, development and education.
- __________________________________________________________________
+ Wireshark is the world’s most popular network protocol analyzer.
+ It is used for troubleshooting, analysis, development and
+ education.
-What's New
+ What’s New
+
+ Wireshark 2.6 is the last release that will support the legacy
+ (GTK+) user interface. It will not be supported or available in
+ Wireshark 3.0.
+
+ Many user interface improvements have been made. See the “New
+ and Updated Features” section below for more details.
+
+ Dumpcap might not quit if Wireshark or TShark crashes. (Bug
+ 1419[1])
New and Updated Features
- The following features are new (or have been significantly updated)
- since version 2.0.0:
- * You can now switch between between Capture and File Format
- dissection of the current capture file via the View menu in the Qt
- GUI.
- * You can now show selected packet bytes as ASCII, HTML, Image, ISO
- 8859-1, Raw, UTF-8, a C array, or YAML.
- * You can now use regular expressions in Find Packet and in the
- advanced preferences.
- * Name resolution for packet capture now supports asynchronous DNS
- lookups only. Therefore the "concurrent DNS resolution" preference
- has been deprecated and is a no-op. To enable DNS name resolution
- some build dependencies must be present (currently c-ares). If that
- is not the case DNS name resolution will be disabled (but other
- name resolution mechanisms, such as host files, are still
- available).
- * The byte under the mouse in the Packet Bytes pane is now
- highlighted.
- * TShark supports exporting PDUs via the -U flag.
- * The Windows and OS X installers now come with the "sshdump" and
- "ciscodump" extcap interfaces.
- * Most dialogs in the Qt UI now save their size and positions.
- * The Follow Stream dialog now supports UTF-16.
- * The Firewall ACL Rules dialog has returned.
- * The Flow (Sequence) Analysis dialog has been improved.
-
- New File Format Decoding Support
-
- Wireshark is able to display the format of some types of files (rather
- than displaying the contents of those files). This is useful when
- you're curious about, or debugging, a file and its format. To open a
- capture file (such as PCAP) in this mode specify "MIME Files Format" as
- the file's format in the Open File dialog.
-
- New files that Wireshark can open in this mode include:
+ The following features are new (or have been significantly
+ updated) since version 2.5.0:
- New Protocol Support
+ • HTTP Referer statistics are now supported.
- Apache Cassandra - CQL version 3.0, Bachmann bluecom Protocol,
- Bluetooth Pseudoheader for BR/EDR, CISCO ERSPAN3 Marker, Edge Control
- Protocol (ECP), Ericsson IPOS Kernel Packet Header Dissector Added
- (IPOS), Extensible Control & Management Protocol (eCMP), FLEXRAY
- Protocol dissector added (automotive bus), ISO 8583-1, ISO14443, ITU-T
- G.7041/Y.1303 Generic Framing Procedure (GFP), LAT protocol (DECNET),
- Metamako trailers, Nokia Intelligent Service Interface (ISI), Open
- Mobile Alliance Lightweight Machine to Machine TLV payload Added (LwM2M
- TLV), RTI TCP Transport Layer (RTITCP), STANAG 5602 SIMPLE, USB3 Vision
- Protocol (USB machine vision cameras), USBIP Protocol, UserLog
- Protocol, and Zigbee Protocol Clusters Dissectors Added (Closures
- Lighting General Measurement & Sensing HVAC Security & Safety)
+ • Wireshark now supports MaxMind DB files. Support for GeoIP
+ and GeoLite Legacy databases has been removed.
- Updated Protocol Support
+ • The Windows packages are now built using Microsoft Visual
+ Studio 2017.
- Bluetooth OBEX dissector (btobex) was renamed to Obex Dissector (obex),
- allow to DecodeAs it over USB, TCP and UDP.
+ • The IP map feature (the “Map” button in the “Endpoints”
+ dialog) has been removed.
- A preference was added to TCP dissector for handling IPFIX process
- information. It has been disabled by default.
+ The following features are new (or have been significantly
+ updated) since version 2.4.0:
- New and Updated Capture File Support
+ • Display filter buttons can now be edited, disabled, and
+ removed via a context menu directly from the toolbar
- and Micropross mplog
+ • Drag & Drop filter fields to the display filter toolbar or
+ edit to create a button on the fly or apply the filter as a
+ display filter.
- New and Updated Capture Interfaces support
+ • Application startup time has been reduced.
- Non-empty section placeholder.
+ • Some keyboard shortcut mix-ups have been resolved by
+ assigning new shortcuts to Edit → Copy methods.
- Major API Changes
+ • TShark now supports color using the --color option.
- The libwireshark API has undergone some major changes:
- * The address macros (e.g., SET_ADDRESS) have been removed. Use the
- (lower case) functions of the same names instead.
- * "old style" dissector functions (that don't return number of bytes
- used) have been replaced in name with the "new style" dissector
- functions.
- * tvb_get_string and tvb_get_stringz have been replaced with
- tvb_get_string_enc and tvb_get_stringz_enc respectively.
- __________________________________________________________________
+ • The "matches" display filter operator is now
+ case-insensitive.
-Getting Wireshark
+ • Display expression (button) preferences have been converted
+ to a UAT. This puts the display expressions in their own
+ file. Wireshark still supports preference files that
+ contain the old preferences, but new preference files will
+ be written without the old fields.
- Wireshark source code and installation packages are available from
- [1]https://www.wireshark.org/download.html.
+ • SMI private enterprise numbers are now read from the
+ "enterprises.tsv" configuration file.
- Vendor-supplied Packages
+ • The QUIC dissector has been renamed to Google QUIC (quic →
+ gquic).
+
+ • The selected packet number can now be shown in the Status
+ Bar by enabling Preferences → Appearance → Layout → Show
+ selected packet number.
+
+ • File load time in the Status Bar is now disabled by default
+ and can be enabled in Preferences → Appearance → Layout →
+ Show file load time.
+
+ • Support for the G.729A codec in the RTP Player is now added
+ via the bcg729 library.
+
+ • Support for hardware-timestamping of packets has been
+ added.
+
+ • Improved NetMon .cap support with comments, event tracing,
+ network filter, network info types and some Message
+ Analyzer exported types.
+
+ • The personal plugins folder on Linux/Unix is now
+ ~/.local/lib/wireshark/plugins.
+
+ • TShark can print flow graphs using -z flow…
+
+ • Capinfos now prints SHA256 hashes in addition to RIPEMD160
+ and SHA1. MD5 output has been removed.
+
+ • The packet editor has been removed. (This was a GTK+ only
+ experimental feature.)
- Most Linux and Unix vendors supply their own Wireshark packages. You
- can usually install or upgrade Wireshark using the package management
- system specific to that platform. A list of third-party packages can be
- found on the [2]download page on the Wireshark web site.
- __________________________________________________________________
+ • Support BBC micro:bit Bluetooth profile
-File Locations
+ • The Linux and UNIX installation step for Wireshark will now
+ install headers required to build plugins. A pkg-config
+ file is provided to help with this (see doc/plugins.example
+ for details). Note you must still rebuild all plugins
+ between minor releases (X.Y).
- Wireshark and TShark look in several different locations for preference
- files, plugins, SNMP MIBS, and RADIUS dictionaries. These locations
- vary from platform to platform. You can use About->Folders to find the
- default locations on your system.
- __________________________________________________________________
+ • The Windows installers and packages now ship with Qt 5.9.4.
+
+ • The generic data dissector can now uncompress zlib
+ compressed data.
+
+ New Protocol Support
+
+ ActiveMQ Artemis Core Protocol, AMT (Automatic Multicast
+ Tunneling), Bluetooth Mesh, Broadcom tags (Broadcom Ethernet
+ switch management frames), CAN-ETH, CVS password server,
+ Excentis DOCSIS31 XRA header, F5ethtrailer, FP Mux, GRPC
+ (gRPC), IEEE 1905.1a, IEEE 802.11ax (High Efficiency WLAN
+ (HEW)), IEEE 802.15.9 IEEE Recommended Practice for Transport
+ of Key Management Protocol (KMP) Datagrams, IEEE 802.3br Frame
+ Preemption Protocol, ISOBUS, LoRaTap, LoRaWAN, Lustre
+ Filesystem, Lustre Network, Nano / RaiBlocks Cryptocurrency
+ Protocol (UDP), Network Functional Application Platform
+ Interface (NFAPI) Protocol, New Radio Radio Resource Control
+ protocol, NXP 802.15.4 Sniffer Protocol, PFCP (Packet
+ Forwarding Control Protocol), Protobuf (Protocol Buffers), QUIC
+ (IETF), RFC 4108 Using CMS to Protect Firmware Packages,
+ Session Multiplex Protocol, SolarEdge monitoring protocol,
+ Steam In-Home Streaming Discovery Protocol, Tibia, TWAMP and
+ OWAMP, Wi-Fi Device Provisioning Protocol, and Wi-SUN FAN
+ Protocol
+
+ Updated Protocol Support
+
+ Too many protocols have been updated to list here.
+
+ New and Updated Capture File Support
+
+ Microsoft Network Monitor
+
+ New and Updated Capture Interfaces support
+
+ LoRaTap
+
+ Getting Wireshark
+
+ Wireshark source code and installation packages are available
+ from https://www.wireshark.org/download.html[2].
+
+ Vendor-supplied Packages
-Known Problems
+ Most Linux and Unix vendors supply their own Wireshark
+ packages. You can usually install or upgrade Wireshark using
+ the package management system specific to that platform. A list
+ of third-party packages can be found on the download page[3] on
+ the Wireshark web site.
- Dumpcap might not quit if Wireshark or TShark crashes. ([3]Bug 1419)
+ File Locations
- The BER dissector might infinitely loop. ([4]Bug 1516)
+ Wireshark and TShark look in several different locations for
+ preference files, plugins, SNMP MIBS, and RADIUS dictionaries.
+ These locations vary from platform to platform. You can use
+ About→Folders to find the default locations on your system.
- Capture filters aren't applied when capturing from named pipes. ([5]Bug
- 1814)
+ Known Problems
- Filtering tshark captures with read filters (-R) no longer works.
- ([6]Bug 2234)
+ The BER dissector might infinitely loop. (Bug 1516[4])
- Application crash when changing real-time option. ([7]Bug 4035)
+ Capture filters aren’t applied when capturing from named pipes.
+ (Bug 1814[5])
- Packet list rows are oversized. ([8]Bug 4357)
+ Filtering tshark captures with read filters (-R) no longer
+ works. (Bug 2234[6])
- Wireshark and TShark will display incorrect delta times in some cases.
- ([9]Bug 4985)
+ Application crash when changing real-time option. (Bug 4035[7])
- Wireshark should let you work with multiple capture files. ([10]Bug
- 10488)
+ Wireshark and TShark will display incorrect delta times in some
+ cases. (Bug 4985[8])
- Dell Backup and Recovery (DBAR) makes many Windows applications crash,
- including Wireshark. ([11]Bug 12036)
- __________________________________________________________________
+ Wireshark should let you work with multiple capture files. (Bug
+ 10488[9])
-Getting Help
+ Getting Help
- Community support is available on [12]Wireshark's Q&A site and on the
- wireshark-users mailing list. Subscription information and archives for
- all of Wireshark's mailing lists can be found on [13]the web site.
+ Community support is available on Wireshark’s Q&A site[10] and
+ on the wireshark-users mailing list. Subscription information
+ and archives for all of Wireshark’s mailing lists can be found
+ on the web site[11].
- Official Wireshark training and certification are available from
- [14]Wireshark University.
- __________________________________________________________________
+ Official Wireshark training and certification are available from
+ Wireshark University[12].
-Frequently Asked Questions
+ Frequently Asked Questions
- A complete FAQ is available on the [15]Wireshark web site.
- __________________________________________________________________
+ A complete FAQ is available on the Wireshark web site[13].
- Last updated 2016-06-08 17:56:17 UTC
+ Last updated 2018-03-13 19:13:27 UTC
-References
+ References
- 1. https://www.wireshark.org/download.html
- 2. https://www.wireshark.org/download.html#thirdparty
- 3. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1419
+ 1. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1419
+ 2. https://www.wireshark.org/download.html
+ 3. https://www.wireshark.org/download.html#thirdparty
4. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1516
5. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1814
6. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2234
7. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4035
- 8. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4357
- 9. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4985
- 10. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10488
- 11. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12036
- 12. https://ask.wireshark.org/
- 13. https://www.wireshark.org/lists/
- 14. http://www.wiresharktraining.com/
- 15. https://www.wireshark.org/faq.html
+ 8. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4985
+ 9. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10488
+ 10. https://ask.wireshark.org/
+ 11. https://www.wireshark.org/lists/
+ 12. http://www.wiresharktraining.com/
+ 13. https://www.wireshark.org/faq.html