1 Wireshark 1.99.9 Release Notes
3 This is a semi-experimental release intended to test new features for
5 __________________________________________________________________
9 Wireshark is the world's most popular network protocol analyzer. It is
10 used for troubleshooting, analysis, development and education.
11 __________________________________________________________________
15 New and Updated Features
17 The following features are new (or have been significantly updated)
20 + The MTP3 statistics and summary dialogs have been added.
21 + The WAP-WSP statistics dialog has been added.
22 + The UDP multicast statistics dialog has been added.
23 + The WLAN statistics dialog has been added.
24 + The display filter macros dialog has been added.
25 + The capture file properties dialog now includes packet
27 + Many more statistics dialogs can be opened from the command
29 + Most dialogs now have a cancellable progress bar.
30 + Many packet list and packet detail context menus items have
32 + Lua plugins can be reloaded from the Analyze menu.
33 + Many bug fixes and improvements.
35 The following features are new (or have been significantly updated)
38 + The Enabled Protocols dialog has been added.
39 + Many statistics dialogs have been added, including Service
40 response time, DHCP/BOOTP, and ANSI.
41 + The RTP Analysis dialog has been added.
42 + Lua dialog support has been added.
43 + You can now manually resolve addresses.
44 + The Resolved Addresses dialog has been added.
45 + The packet list scrollbar now has a minimap.
46 + The capture interfaces dialog has been updated.
47 + You can now colorize conversations.
48 + Welcome screen behavior has been improved.
49 + Plugin support has been improved.
50 + Many dialogs should now more correctly minimize and maximize.
51 + The reload button has been added back to the toolbar.
52 + The "Decode As" dialog no longer saves decoding behavior.
53 + You can now stop loading large capture files.
54 + The Bluetooth HCI Summary has been added.
56 The following features are new (or have been significantly updated)
59 + The Bluetooth Devices dialog has been added.
60 + The wireless toolbar has been added.
61 + Opening files via drag and drop is now supported.
62 + The Capture Filter and Display Filter dialogs have been added.
63 + The Display Filter Expression dialog has been added.
64 + Conversation Filter menu items have been added.
65 + You can change protocol preferences by right clicking on the
66 packet list and details.
68 The following features are new (or have been significantly updated)
69 since version 1.99.4 and 1.99.5:
71 + Capture restarts are now supported.
72 + Menu items for plugins are now supported.
73 + Extcap interfaces are now supported.
74 + The Expert Information dialog has been added.
75 + Display and capture filter completion is now supported.
76 + Many bugs have been fixed.
77 + Translations have been updated.
79 The following features are new (or have been significantly updated)
82 + Several interface bugs have been fixed.
83 + Translations have been updated.
85 The following features are new (or have been significantly updated)
88 + Several bugs have been fixed.
89 + You can now open a packet in a new window.
90 + The Bluetooth ATT Server Attributes dialog has been added.
91 + The Coloring Rules dialog has been added.
92 + Many translations have been updated. Chinese, Italian and
93 Polish translations are complete.
94 + General user interface and usability improvements.
95 + Automatic scrolling during capture now works.
96 + The related packet indicator has been updated.
98 The following features are new (or have been significantly updated)
101 + The welcome screen layout has been updated.
102 + The Preferences dialog no longer crashes on Windows.
103 + The packet list header menu has been added.
104 + Statistics tree plugins are now supported.
105 + The window icon is now displayed properly in the Windows
107 + A packet list an byte view selection bug has been fixed
109 + The RTP Streams dialog has been added.
110 + The Protocol Hierarchy Statistics dialog has been added.
112 The following features are new (or have been significantly updated)
113 since version 1.99.0:
115 + You can now show and hide toolbars and major widgets using the
117 + You can now set the time display format and precision.
118 + The byte view widget is much faster, particularly when
119 selecting large reassembled packets.
120 + The byte view is explorable. Hovering over it highlights the
121 corresponding field and shows a description in the status bar.
122 + An Italian translation has been added.
123 + The Summary dialog has been updated and renamed to Capture
125 + The VoIP Calls and SIP Flows dialogs have been added.
126 + Support for HiDPI / Retina displays has been improved in the
128 * DNS stats: + A new stats tree has been added to the Statistics
129 menu. Now it is possible to collect stats such as qtype/qclass
130 distribution, number of resource record per response section, and
131 stats data (min, max, avg) for values such as query name length or
133 * HPFEEDS stats: + A new stats tree has been added to the statistics
134 menu. Now it is possible to collect stats per channel (messages
135 count and payload size), and opcode distribution.
136 * HTTP2 stats: + A new stats tree has been added to the statistics
137 menu. Now it is possible to collect stats (type distribution).
139 The following features are new (or have been significantly updated)
140 since version 1.12.0:
141 * The I/O Graph in the Gtk+ UI now supports an unlimited number of
142 data points (up from 100k).
143 * TShark now resets its state when changing files in ring-buffer
145 * Expert Info severities can now be configured.
146 * Wireshark now supports external capture interfaces. External
147 capture interfaces can be anything from a tcpdump-over-ssh pipe to
148 a program that captures from proprietary or non-standard hardware.
149 This functionality is not available in the Qt UI yet.
151 + The Qt UI is now the default (program name is wireshark).
152 + A Polish translation has been added.
153 + The Interfaces dialog has been added.
154 + The interface list is now updated when interfaces appear or
156 + The Conversations and Endpoints dialogs have been added.
157 + A Japanese translation has been added.
158 + It is now possible to manage remote capture interfaces.
159 + Windows: taskbar progress support has been added.
160 + Most toolbar actions are in place and work.
161 + More command line options are now supported
163 New File Format Support
165 BTSNOOP, PCAP, and PCAPNG
169 (LISP) TCP Control Message, Aeron, AllJoyn Reliable Datagram Protocol,
170 Android ADB, Android Logcat text, Apache Tribes Heartbeat, BGP
171 Monitoring Prototol (BMP), C15 Call History Protocol dissection
172 (C15ch), ceph, Concise Binary Object Representation (CBOR) (RFC 7049),
173 corosync/totemnet corosync cluster engine ( lowest
174 levelencryption/decryption protocol), corosync/totemsrp corosync
175 cluster engine ( totem single ring protocol), Couchbase, CP "Cooper"
176 2179, DJI UAV Drone Control Protocol, Dynamic Source Routing (RFC
177 4728), Elasticsearch, ETSI Card Application Toolkit - Transport
178 Protocol, eXpressive Internet Protocol (XIP), Generic Network
179 Virtualization Encapsulation (Geneve), Geospatial and Imagery Access
180 Service (GIAS), GVSP GigE Vision (TM) Streaming Protocol, HCrt, HiQnet,
181 IP Detail Record (IPDR), IPMI Trace, iSER, KNXnetIP, MACsec Key
182 Agreement - EAPoL-MKA, MCPE (Minecraft Pocket Edition), Message Queuing
183 Telemetry Transport For Sensor Networks (MQTT-SN), Network File System
184 over Remote Direct Memory Access (NFSoRDMA), OCFS2, OptoMMP,
185 Performance Co-Pilot Proxy, QNEX6 (QNET), RakNet games library, Remote
186 Shared Virtual Disk - RSVD, Riemann, S7 Communication, Secure Socket
187 Tunnel Protocol (SSTP), Shared Memory Communications - RDMA, Stateless
188 Transport Tunneling, Thrift, Time Division Multiplexing over Packet
189 Network (TDMoP), Video Services over IP (VSIP), Windows Search Protocol
190 (MS-WSP), and ZVT Kassenschnittstelle
192 Updated Protocol Support
194 Too many protocols have been updated to list here.
196 New and Updated Capture File Support
198 3GPP TS 32.423 Trace, Android Logcat text files, Colasoft Capsa files,
199 Netscaler 3.5, and Wireshark now supports nanosecond timestamp
200 resolution in PCAP-NG files.
202 New and Updated Capture Interfaces support
204 and Androiddump - provide interfaces to capture (Logcat and Bluetooth)
205 from connected Android devices
209 The libwireshark API has undergone some major changes:
210 * The emem framework (including all ep_ and se_ memory allocation
211 routines) has been completely removed in favour of wmem which is
213 * The (long-since-broken) Python bindings support has been removed.
214 If you want to write dissectors in something other than C, use Lua.
215 * Plugins can now create GUI menu items.
216 * Heuristic dissectors can now be globally enabled/disabled so
217 heur_dissector_add() has a few more parameters to make that
219 __________________________________________________________________
223 Wireshark source code and installation packages are available from
224 [2]https://www.wireshark.org/download.html.
226 Vendor-supplied Packages
228 Most Linux and Unix vendors supply their own Wireshark packages. You
229 can usually install or upgrade Wireshark using the package management
230 system specific to that platform. A list of third-party packages can be
231 found on the [3]download page on the Wireshark web site.
232 __________________________________________________________________
236 Wireshark and TShark look in several different locations for preference
237 files, plugins, SNMP MIBS, and RADIUS dictionaries. These locations
238 vary from platform to platform. You can use About->Folders to find the
239 default locations on your system.
240 __________________________________________________________________
244 Dumpcap might not quit if Wireshark or TShark crashes. ([4]Bug 1419)
246 The BER dissector might infinitely loop. ([5]Bug 1516)
248 Capture filters aren't applied when capturing from named pipes. ([6]Bug
251 Filtering tshark captures with read filters (-R) no longer works.
254 Resolving ([8]Bug 9044) reopens ([9]Bug 3528) so that Wireshark no
255 longer automatically decodes gzip data when following a TCP stream.
257 Application crash when changing real-time option. ([10]Bug 4035)
259 Hex pane display issue after startup. ([11]Bug 4056)
261 Packet list rows are oversized. ([12]Bug 4357)
263 Wireshark and TShark will display incorrect delta times in some cases.
266 The 64-bit version of Wireshark will leak memory on Windows when the
267 display depth is set to 16 bits ([14]Bug 9914)
269 Wireshark should let you work with multiple capture files. ([15]Bug
271 __________________________________________________________________
275 Community support is available on [16]Wireshark's Q&A site and on the
276 wireshark-users mailing list. Subscription information and archives for
277 all of Wireshark's mailing lists can be found on [17]the web site.
279 Official Wireshark training and certification are available from
280 [18]Wireshark University.
281 __________________________________________________________________
283 Frequently Asked Questions
285 A complete FAQ is available on the [19]Wireshark web site.
286 __________________________________________________________________
288 Last updated 2015-09-01 18:01:23 UTC
292 1. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10896
293 2. https://www.wireshark.org/download.html
294 3. https://www.wireshark.org/download.html#thirdparty
295 4. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1419
296 5. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1516
297 6. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1814
298 7. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2234
299 8. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9044
300 9. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3528
301 10. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4035
302 11. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4056
303 12. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4357
304 13. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4985
305 14. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9914
306 15. https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10488
307 16. https://ask.wireshark.org/
308 17. https://www.wireshark.org/lists/
309 18. http://www.wiresharktraining.com/
310 19. https://www.wireshark.org/faq.html