<!--
Wireshark Info
-->
- <!ENTITY WiresharkCurrentVersion "1.5.0">
+<!ENTITY WiresharkCurrentVersion "1.7.1">
]>
<itemizedlist>
- <listitem><para>
- Wireshark is unresponsive when capturing from named pipes on Windows.
- (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1759">Bug
- 1759</ulink>)
- </para></listitem>
-
<listitem><para>
- Ring buffers are no longer turned on by default when using multiple
- capture files.
+ .
</para></listitem>
</itemizedlist>
<section id="NewFeatures"><title>New and Updated Features</title>
<para>
The following features are new (or have been significantly updated)
- since version 1.4:
+ since version 1.6:
<itemizedlist>
<listitem>
<para>
- Wireshark can import text dumps, similar to text2pcap.
- </para>
- </listitem>
-
- <listitem>
- <para>
- You can now view Wireshark's dissector tables (for example the
- TCP port to dissector mappings) from the main window.
- </para>
- </listitem>
-
- <listitem>
- <para>
- TShark can show a specific occurrence of a field when using '-T fields'.
- </para>
- </listitem>
-
- <listitem>
- <para>
- Custom columns can show a specific occurrence of a field.
- </para>
- </listitem>
-
- <listitem>
- <para>
- You can hide columns in the packet list.
- </para>
- </listitem>
-
- <listitem>
- <para>
- Wireshark can now export SMB objects.
- </para>
- </listitem>
-
- <listitem>
- <para>
- dftest and randpkt now have manual pages.
+ Wireshark supports capturing from multiple interfaces at once.
</para>
</listitem>
<listitem>
<para>
- TShark can now display iSCSI service response times.
+ Wireshark, TShark, and their associated utilities now save files
+ using the pcap-ng file format by default. (Your copy of Wireshark
+ might still use the pcap file format if pcap-ng is disabled in
+ your preferences.)
</para>
</listitem>
-
<listitem>
<para>
- Dumpcap can now save files with a user-specified group id.
+ Decryption key management for IEEE 802.11, IPsec, and ISAKMP
+ is easier.
</para>
</listitem>
<listitem>
<para>
- Syntax checking is done for capture filters.
+ OID resolution is now supported on 64-bit Windows.
</para>
</listitem>
<listitem>
<para>
- You can display the compiled BPF code for capture filters in the
- Capture Options dialog.
+ When saving packets, the default choice is now to save
+ only the displayed packets rather than all packets.
</para>
</listitem>
<listitem>
<para>
- You can now navigate backwards and forwards through TCP and UDP
- sessions using
- <shortcut><keycombo><keycap>Ctrl</keycap><keycap>,</keycap></keycombo></shortcut>
- and
- <shortcut><keycombo><keycap>Ctrl</keycap><keycap>.</keycap></keycombo></shortcut>
- .
+ TCP fast retransmissions are now indicated as an expert info note,
+ rather than a warning, just as TCP retransmissions are.
</para>
</listitem>
<listitem>
<para>
- Packet length is (finally) a default column.
+ TCP window updates are no longer colorized as "Bad TCP".
</para>
</listitem>
<listitem>
<para>
- TCP window size is now avaiable both scaled and unscaled. A TCP
- window scaling graph is available in the GUI.
+ TShark's command-line options have changed. The previously
+ undocumented -P option is now -2 option for performing a two-pass
+ analysis; the former -S option is now the -P option for printing
+ packets even if writing to a file, and the -S option is now used to
+ specify a different line separator between packets.
</para>
</listitem>
- <listitem>
- <para>
- 802.1q VLAN tags are now shown by the Ethernet II dissector.
- </para>
- </listitem>
-
- <listitem>
- <para>
- Various dissectors now display some UTF-16 strings as proper Unicode
- including the DCE/RPC and SMB dissectors.
- </para>
- </listitem>
-
- <listitem>
- <para>
- The RTP player now has an option to show the time of day in the
- graph in addition to the seconds since beginning of capture.
- </para>
- </listitem>
-
<listitem>
<para>
- The RTP player now shows why media interruptions occur.
+ GeoIP IPv6 databases are now supported.
</para>
</listitem>
<section id="NewProtocols"><title>New Protocol Support</title>
<para>
-ADwin,
-ADwin-Config,
-Apache Etch,
-Aruba PAPI,
-Constrained Application Protocol (COAP),
-Digium TDMoE,
-Ether-S-I/O,
-FastCGI,
-Fibre Channel over InfiniBand (FCoIB),
-Gopher,
-Gigamon GMHDR,
-IDMP,
-Infiniband Socket Direct Protocol (SDP),
-JSON,
-MikroTik MAC-Telnet,
-Mongo Wire Protocol,
-Network Monitor 802.11 radio header,
-OPC UA ExtensionObjects,
-PPI-GEOLOCATION-GPS,
-ReLOAD,
-ReLOAD Framing,
-SAMETIME,
-SCoP,
-SGSAP,
-Tektronix Teklink,
-WAI authentication,
-Wi-Fi P2P (Wi-Fi Direct)
+<!-- Sorted, one per line -->
</para>
</section>
<section id="NewCapture"><title>New and Updated Capture File Support</title>
<para>
-Apple PacketLogger,
-Catapult DCT2000,
-Daintree SNA,
-Endace ERF,
-HP OpenVMS TCPTrace,
-IPFIX (the file format, not the protocol),
-Lucent/Ascend debug,
-Microsoft Network Monitor,
-Network Instruments,
-TamoSoft CommView
+<!-- Sorted, one per line -->
</para>
</section>
</para>
<para>
- The 64-bit Windows installer does not ship with libsmi.
+ The 64-bit Windows installer does not support Kerberos decryption.
(<ulink url="http://wiki.wireshark.org/Development/Win64">Win64
development page</ulink>)
</para>
4056</ulink>)
</para>
- <para>
- Crash when sorting column while capturing.
- (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4273">Bug
- 4273</ulink>)
- </para>
-
<para>
Packet list rows are oversized.
(<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4357">Bug
4445</ulink>)
</para>
+ <para>
+ Wireshark and TShark will display incorrect delta times in some cases.
+ (<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5356">Bug
+ 4985</ulink>
+ and
+ <ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5356">bug
+ 5580</ulink>)
+ </para>
+
<para>
Character echo pauses in Capture Filter field in Capture Options.
(<ulink url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5356">Bug