2016-11-01 21:35:29 +00:00
|
|
|
include::attributes.asciidoc[]
|
|
|
|
|
2016-07-16 07:53:37 +00:00
|
|
|
= Wireshark {wireshark-version} Release Notes
|
2014-10-02 21:15:05 +00:00
|
|
|
// AsciiDoc quick reference: http://powerman.name/doc/asciidoc
|
2014-04-15 16:31:24 +00:00
|
|
|
|
2016-07-21 22:53:54 +00:00
|
|
|
This is a semi-experimental release intended to test new features for
|
2017-06-03 18:15:59 +00:00
|
|
|
Wireshark 2.6.
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
== What is Wireshark?
|
|
|
|
|
|
|
|
Wireshark is the world's most popular network protocol analyzer. It is
|
|
|
|
used for troubleshooting, analysis, development and education.
|
|
|
|
|
|
|
|
== What's New
|
|
|
|
|
2018-01-06 01:02:57 +00:00
|
|
|
Many user interface improvements have been made. See the New and Updated
|
|
|
|
Features section below for more details.
|
2017-09-02 23:42:00 +00:00
|
|
|
|
2014-10-02 21:15:05 +00:00
|
|
|
//=== Bug Fixes
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2014-10-01 15:17:44 +00:00
|
|
|
//The following bugs have been fixed:
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2013-03-15 18:25:42 +00:00
|
|
|
//* ws-buglink:5000[]
|
|
|
|
//* ws-buglink:6000[Wireshark bug]
|
2014-05-23 20:56:41 +00:00
|
|
|
//* cve-idlink:2014-2486[]
|
2017-06-02 22:39:32 +00:00
|
|
|
//* Wireshark convinced you to switch seats on the plane while neglecting to tell you that its seat was noticeably moist.
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2016-06-08 16:15:24 +00:00
|
|
|
//_Non-empty section placeholder._
|
2015-10-13 21:59:56 +00:00
|
|
|
|
2013-03-15 01:33:46 +00:00
|
|
|
=== New and Updated Features
|
|
|
|
|
2016-07-14 21:06:14 +00:00
|
|
|
The following features are new (or have been significantly updated)
|
2017-06-03 18:15:59 +00:00
|
|
|
since version 2.4.0:
|
2018-01-06 01:02:57 +00:00
|
|
|
* Display filter buttons can now be edited, disabled, and removed via a context
|
|
|
|
menu directly from the toolbar
|
|
|
|
* Drag & Drop filter fields to the display filter toolbar or edit to create
|
|
|
|
a button on the fly or apply the filter as a display filter.
|
|
|
|
* Application startup time has been reduced.
|
|
|
|
* Some keyboard shortcut mix-ups have been resolved by assigning new shortcuts
|
|
|
|
to Edit -> Copy methods.
|
|
|
|
* TShark now supports color using the --color option.
|
2017-06-21 21:34:30 +00:00
|
|
|
* The "matches" display filter operator is now case-insensitive.
|
2017-06-22 15:34:48 +00:00
|
|
|
* Display expression (button) preferences have been converted to a UAT.
|
|
|
|
This puts the display expressions in their own file. Wireshark still
|
|
|
|
supports preference files that contain the old preferences, but new
|
|
|
|
preference files will be written without the old fields.
|
2017-07-13 20:03:13 +00:00
|
|
|
* SMI private enterprise numbers are now read from the "enterprises.tsv" configuration file.
|
2018-01-06 01:02:57 +00:00
|
|
|
* The QUIC dissector has been renamed to G(oogle) QUIC (quic => gquic).
|
|
|
|
* The selected packet number can now be shown in the Status Bar by enabling
|
2017-07-30 10:15:02 +00:00
|
|
|
Preferences -> Appearance -> Layout -> Show selected packet number.
|
2018-01-06 01:02:57 +00:00
|
|
|
* File load time in the Status Bar is now disabled by default and can be enabled in
|
2017-07-30 10:15:02 +00:00
|
|
|
Preferences -> Appearance -> Layout -> Show file load time.
|
2018-01-06 01:02:57 +00:00
|
|
|
* Support for the G.729 codec in the RTP Player is now supported via the bcg729 library.
|
|
|
|
* Support for hardware-timestamping of packets has been added.
|
2017-09-04 14:16:49 +00:00
|
|
|
* Improved NetMon .cap support with comments, event tracing, network filter,
|
|
|
|
network info types and some Message Analyzer exported types.
|
2018-01-06 01:02:57 +00:00
|
|
|
* The personal plugins folder on Linux/Unix is now ~/.local/lib/wireshark/plugins.
|
|
|
|
* TShark can print flow graphs using -z flow...
|
2017-09-26 21:23:51 +00:00
|
|
|
* Capinfos now prints SHA256 hashes in addition to RIPEMD160 and SHA1. MD5 output
|
|
|
|
has been removed.
|
2018-01-06 01:02:57 +00:00
|
|
|
* The packet editor has been removed (GTK only experimental feature).
|
2018-01-04 08:26:20 +00:00
|
|
|
* Support BBC micro:bit Bluetooth profile
|
2018-01-06 01:02:57 +00:00
|
|
|
* The Linux and UNIX installation step for Wireshark will now install
|
|
|
|
headers required to build plugins. A pkg-config file is provided to
|
|
|
|
help with this (see doc/plugins.example for details). Note you must
|
|
|
|
still rebuild all plugins between minor releases (X.Y).
|
2015-06-29 11:05:32 +00:00
|
|
|
|
2014-06-06 18:39:55 +00:00
|
|
|
//=== Removed Dissectors
|
2014-01-03 09:48:53 +00:00
|
|
|
|
2016-08-16 14:50:37 +00:00
|
|
|
//=== New File Format Decoding Support
|
2014-01-03 09:48:53 +00:00
|
|
|
|
2013-03-15 01:33:46 +00:00
|
|
|
=== New Protocol Support
|
2016-06-03 16:21:21 +00:00
|
|
|
|
2016-06-08 16:15:24 +00:00
|
|
|
// Add one protocol per line between the --sort-and-group-- delimiters.
|
2016-06-03 16:21:21 +00:00
|
|
|
--sort-and-group--
|
2018-01-06 01:02:57 +00:00
|
|
|
ActiveMQ Artemis Core Protocol
|
2017-07-11 20:44:18 +00:00
|
|
|
AMT (Automatic Multicast Tunneling)
|
2018-01-06 01:02:57 +00:00
|
|
|
Bluetooth Mesh
|
2017-09-17 04:45:49 +00:00
|
|
|
Broadcom tags (Broadcom Ethernet switch management frames)
|
2017-10-06 12:01:43 +00:00
|
|
|
FP Mux
|
2018-01-06 01:02:57 +00:00
|
|
|
GRPC (gRPC)
|
2017-10-26 02:38:33 +00:00
|
|
|
IEEE 1905.1a
|
2017-12-18 15:25:18 +00:00
|
|
|
IEEE 802.3br Frame Preemption Protocol
|
2018-01-06 01:02:57 +00:00
|
|
|
ISOBUS
|
|
|
|
LoRaTap
|
|
|
|
LoRaWAN
|
2017-11-02 15:47:33 +00:00
|
|
|
Lustre Network
|
2017-12-19 18:06:46 +00:00
|
|
|
Lustre Filesystem
|
2018-01-06 01:02:57 +00:00
|
|
|
Network Functional Application Platform Interface (NFAPI) Protocol
|
2017-12-31 17:23:53 +00:00
|
|
|
NXP 802.15.4 Sniffer Protocol
|
2018-01-06 01:02:57 +00:00
|
|
|
PFCP (Packet Forwarding Control Protocol)
|
|
|
|
Protobuf (Protocol Buffers)
|
|
|
|
QUIC (IETF)
|
|
|
|
SolarEdge monitoring protocol
|
|
|
|
Tibia
|
|
|
|
TWAMP and OWAMP
|
|
|
|
Wi-Fi Device Provisioning Protocol
|
2013-03-18 22:17:42 +00:00
|
|
|
--sort-and-group--
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
=== Updated Protocol Support
|
|
|
|
|
2016-08-16 14:50:37 +00:00
|
|
|
Too many protocols have been updated to list here.
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
=== New and Updated Capture File Support
|
|
|
|
|
2018-01-06 01:02:57 +00:00
|
|
|
//_Non-empty section placeholder._
|
2016-06-08 16:15:24 +00:00
|
|
|
// Add one file type per line between the --sort-and-group-- delimiters.
|
2014-09-29 15:05:38 +00:00
|
|
|
--sort-and-group--
|
2018-01-06 01:02:57 +00:00
|
|
|
Microsoft Network Monitor
|
2014-09-29 15:05:38 +00:00
|
|
|
--sort-and-group--
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2015-04-08 14:09:03 +00:00
|
|
|
=== New and Updated Capture Interfaces support
|
|
|
|
|
2018-01-06 01:02:57 +00:00
|
|
|
//_Non-empty section placeholder._
|
2015-04-08 14:09:03 +00:00
|
|
|
--sort-and-group--
|
2017-06-03 15:22:48 +00:00
|
|
|
LoRaTap
|
2015-04-08 14:09:03 +00:00
|
|
|
--sort-and-group--
|
|
|
|
|
2016-08-16 14:50:37 +00:00
|
|
|
//=== Major API Changes
|
2014-02-22 19:16:44 +00:00
|
|
|
|
2013-03-15 01:33:46 +00:00
|
|
|
== Getting Wireshark
|
|
|
|
|
|
|
|
Wireshark source code and installation packages are available from
|
2014-09-17 00:15:56 +00:00
|
|
|
https://www.wireshark.org/download.html.
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
=== Vendor-supplied Packages
|
|
|
|
|
|
|
|
Most Linux and Unix vendors supply their own Wireshark packages. You can
|
|
|
|
usually install or upgrade Wireshark using the package management system
|
|
|
|
specific to that platform. A list of third-party packages can be found
|
2014-09-17 00:15:56 +00:00
|
|
|
on the https://www.wireshark.org/download.html#thirdparty[download page]
|
2013-03-15 01:33:46 +00:00
|
|
|
on the Wireshark web site.
|
|
|
|
|
|
|
|
== File Locations
|
|
|
|
|
|
|
|
Wireshark and TShark look in several different locations for preference
|
|
|
|
files, plugins, SNMP MIBS, and RADIUS dictionaries. These locations vary
|
|
|
|
from platform to platform. You can use About→Folders to find the default
|
|
|
|
locations on your system.
|
|
|
|
|
|
|
|
== Known Problems
|
|
|
|
|
|
|
|
Dumpcap might not quit if Wireshark or TShark crashes.
|
2013-03-15 18:25:07 +00:00
|
|
|
(ws-buglink:1419[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
The BER dissector might infinitely loop.
|
2013-03-15 18:25:07 +00:00
|
|
|
(ws-buglink:1516[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
Capture filters aren't applied when capturing from named pipes.
|
2014-10-01 15:17:44 +00:00
|
|
|
(ws-buglink:1814[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2013-03-28 21:46:37 +00:00
|
|
|
Filtering tshark captures with read filters (-R) no longer works.
|
2013-03-15 18:25:07 +00:00
|
|
|
(ws-buglink:2234[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
Application crash when changing real-time option.
|
2013-03-15 18:25:07 +00:00
|
|
|
(ws-buglink:4035[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
Wireshark and TShark will display incorrect delta times in some cases.
|
2013-03-15 18:25:07 +00:00
|
|
|
(ws-buglink:4985[])
|
2013-03-15 01:33:46 +00:00
|
|
|
|
2014-12-15 17:24:01 +00:00
|
|
|
Wireshark should let you work with multiple capture files. (ws-buglink:10488[])
|
|
|
|
|
2013-03-15 01:33:46 +00:00
|
|
|
== Getting Help
|
|
|
|
|
2015-03-10 17:46:50 +00:00
|
|
|
Community support is available on https://ask.wireshark.org/[Wireshark's
|
2013-03-15 01:33:46 +00:00
|
|
|
Q&A site] and on the wireshark-users mailing list. Subscription
|
|
|
|
information and archives for all of Wireshark's mailing lists can be
|
2014-09-17 00:15:56 +00:00
|
|
|
found on https://www.wireshark.org/lists/[the web site].
|
2013-03-15 01:33:46 +00:00
|
|
|
|
|
|
|
Official Wireshark training and certification are available from
|
|
|
|
http://www.wiresharktraining.com/[Wireshark University].
|
|
|
|
|
|
|
|
== Frequently Asked Questions
|
|
|
|
|
|
|
|
A complete FAQ is available on the
|
2014-09-17 00:15:56 +00:00
|
|
|
https://www.wireshark.org/faq.html[Wireshark web site].
|