Maandag is versie 1.01 van de opensource 'protocol analyzer' en packet sniffer Wireshark uitgebracht. Dit programma werd eerst onder de naam Ethereal uitgebracht, maar toen hoofdontwikkelaar en stichter Gerald Combs het bedrijf NIS verruilde voor Cace Technologies, kon hij wel de software meenemen, maar wegens de rechten die er op rusten niet de naam. Wireshark kan worden gebruikt om vele honderden verschillende netwerkprotocollen en datapakketten die over het netwerk wordt verstuurd te ontleden en te analyseren. Tevens kan het ook reeds opgeslagen dataverkeer gebruiken als invoer. Het changelog van deze release laat de volgende veranderingen en verbeteringen zien:
The following vulnerabilities have been fixed:The following bugs have been fixed:
- The GSM SMS dissector could crash.
- The PANA and KISMET dissectors could force Wireshark to quit unexpectedly.
- The RTMPT dissector could crash.
- The RMI dissector could disclose system memory. Discovered by Noam Rathus.
- The syslog dissector could crash.
New and Updated Features
- RPC portmap classification switched to TCP after filtering. (Bug 1392)
- Force the foreground color when the background is forced. (Bug 1735)
- RPC stream shows malformed packets. (Bug 2148)
- SNMP trap dissection fails. (Bug 2253)
- Failure to detect/open valid ERF files. (Bug 2359)
- Window scaling bug. (Bug 2378)
- Bugs in the EIGRP dissector. (Bug 2381)
- E212 Mobile network code 3rd digit is not correctly decoded. (Bug 2393)
- The BOOTP dissector fails to initialize and display some values. (Bug 2395)
- Data string filter crash. (Bug 2402)
- Debian packaging problems. (Bug 2405)
- Expert info composite crash for LDAP. (Bug 2407)
- Statistics > Multicast Streams are broken. (Bug 2414)
- "Read me first" file is empty in the OS X .dmg. (Bug 2425)
- Failed tshark PDML export to file. (Bug 2432)
- RTCP MOS fields display wrong values. (Bug 2440)
- SNMP trap parse error. (Bug 2442)
- Ports incorrectly decoded as DPLAY instead of RTP. (Bug 2452)
- Incorrect decoding of DST MAC address of frame containing ICMPv6 Echo Request. (Bug 2456)
- Fix wireshark-filter man page for packet-diameter_3gpp.c fields. (Bug 2457)
- Dissector bug, protocol SNMP: proto.c:932: failed assertion. (Bug 2468)
- UDP not decoded as UNIStim. (Bug 2475)
- Debug text output from MIKEY dissector. (Bug 2481)
- Windows compilation errors with flex 2.5.35. (Bug 2493)
- RTP heuristic interferes with STUN/T38 portion of heuristic. (Bug 2497)
- WiMAX dissector assertion. (Bug 2501)
- RTP header extensions with length>4 bytes dissected incorrectly. (Bug 2505)
- Compilation failure on non-european Windows systems. (Bug 2513)
- BACnet BVLC NAK decoding. (Bug 2517)
- 'tshark -Tfields -e data' omits last character of data. (Bug 2518)
- "Next file every" inconsistent behaviour. (Bug 2599)
- Wireshark doest not parse iSCSI login PDU. (Bug 2616)
- URL and encoding for OUI listings in make-manuf. (Bug 2619)
New Protocol Support
- The following features are new (or have been significantly updated) since the last release:
- The "About" box finally displays version 1.0.
- Wireshark now supports custom columns.
- This release includes an experimental Mac OS X package.
Updated Protocol Support
- There are no new protocols in this release.
New and Updated Capture File Support
- ACTRACE, BACnet BVLC, BOOTP, E212, iSCSI, IUA, LDAP, MGCP, MIKEY, MSMMS, RMI, RPC, RTCP, RTP, SIP, SNMP, TCP, UNIStim, WiMAX
[break]
- Endace ERF
Wireshark onder Ubuntu, klik op de afbeelding voor een grotere versie.