Anzeigen der neuesten Beiträge
0 Mitglieder und 1 Gast betrachten dieses Thema.
Bug Fixes The following bugs have been fixed: New and Updated Features The following features are new (or have been significantly updated) since version 1.8: * Wireshark on 32- and 64-bit Windows supports automatic updates. * The packet bytes view is faster. * You can now display a list of resolved host names in "hosts" format within Wireshark. * The wireless toolbar has been updated. * Wireshark on Linux does a better job of detecting interface addition and removal. * It is now possible to compare two fields in a display filter (for example: udp.srcport != udp.dstport). The two fields must be of the same type for this to work. * The Windows installers ship with WinPcap 4.1.3, which supports Windows 8. * USB type and product name support has been improved. * Wireshark now calculates HTTP response times and presents the result in a new field in the HTTP response. Links from the request's frame to the response's frame and vice-versa are also added. * The main welcome screen and status bar now display file sizes using strict SI prefixes instead of old-style binary prefixes. * Capinfos now prints human-readable statistics with SI suffixes by default. * It is now possible to open a referenced packet (such as the matched request or response packet) in a new window. * It is now possible for tshark to display only the hex/ascii packet data without also requiring that the packet summary and/or packet details are also displayed. If you want the old behavior, use -Px instead of just -x. * The Wireshark application icon, capture toolbar icons, and other icons have been updated.
Bug Fixes The following bugs have been fixed: New and Updated Features The following features are new (or have been significantly updated) since version 1.8: * Wireshark on 32- and 64-bit Windows supports automatic updates. * The packet bytes view is faster. * You can now display a list of resolved host names in "hosts" format within Wireshark. * The wireless toolbar has been updated. * Wireshark on Linux does a better job of detecting interface addition and removal. * It is now possible to compare two fields in a display filter (for example: udp.srcport != udp.dstport). The two fields must be of the same type for this to work. * The Windows installers ship with WinPcap 4.1.3, which supports Windows 8. * USB type and product name support has been improved. * All Bluetooth profiles and protocols are now supported. * Wireshark now calculates HTTP response times and presents the result in a new field in the HTTP response. Links from the request's frame to the response's frame and vice-versa are also added. * The main welcome screen and status bar now display file sizes using strict SI prefixes instead of old-style binary prefixes. * Capinfos now prints human-readable statistics with SI suffixes by default. * It is now possible to open a referenced packet (such as the matched request or response packet) in a new window. * Tshark can now display only the hex/ascii packet data without requiring that the packet summary and/or packet details are also displayed. If you want the old behavior, use -Px instead of just -x. * Wireshark can be compiled using GTK+ 3. * The Wireshark application icon, capture toolbar icons, and other icons have been updated. * Tshark's filtering and multi-pass analysis have been reworked for consistency and in order to support dependent frame calculations during reassembly. See the man page descriptions for -2, -R, and -Y. * Tshark's -G fields2 and -G fields3 options have been eliminated. The -G fields option now includes the 2 extra fields that -G fields3 previously provided, and the blurb information has been relegated to the last column since in many cases it is blank anyway.
# The following vulnerabilities have been fixed.- The Bluetooth HCI ACL dissector could crash.- The NBAP dissector could crash.- The ASSA R3 dissector could go into an infinite loop.- The RTPS dissector could overflow a buffer.- The MQ dissector could crash.- The LDAP dissector could crash.- The Netmon file parser could crash.# The following bugs have been fixed:- Lua ByteArray:append() causes wireshark crash.- Lua script can not get "data-text-lines" protocol data.- Lua: Trying to use Field.new("tcp.segments") to get reassembled TCP data is failed.- "Edit Interface Settings": "Capture Filter" combo box is not populated across Wireshark sessions.- PER normally small non-negative whole number decoding is wrong when >= 64.- Strange behavior of tree expand/collapse in packet details.- Incorrect parsing of IPFIX *IpTotalLength elements.- IO graph/advanced, max/min/summ error on frames with multiple Diameter messages.- pod2man error on reordercap.pod.- SGI Nsym disambiguation is unconditionally displayed when dissecting VHT.- The Wireshark icon doesn’t show up in OS X 10.5.- Build fails if system Python is version 3+.- SCSI dissector does not parse PERSISTENT RESERVE commands correctly.- SDP messages throws an assert.- Wireshark fails to decode single-line, multiple Contact: URIs in SIP responses.- PN_MRP LinkUp Message is shown as LinkDown in info.- Dissector for EtherCAT: ADS highlighting in the Packet Bytes Pane is incorrect.- 802.11 HT Extended Capabilities B10 decode incorrect.- Wrong dissection of MSTI Root Identifiers for all MSTIs.- Weird malformed HTTP error.- Warning for attempting to install 64-bit Wireshark on a 32-bit machine has an embedded "\n".- Wireshark crashes when using "Export Specified Packets" > "Displayed".# Updated Protocol Support- ASN.1 PER, ASSA R3, Bluetooth HCI ACL, EtherCAT AMS, GTPv2, HTTP, IEEE 802.11, IPFIX, ISDN SUP, LDAP, MQ, NBAP, Novell SSS, PROFINET MRP, Radiotap, ROHC, RTPS, SCSI, SIP, and STP# New and Updated Capture File Support- Microsoft Network Monitor, pcap-ng.
Bug Fixes:The following bugs have been fixed:"Follow TCP Stream" shows only the first HTTP req+res.Files with pcap-ng Simple Packet Blocks can't be read.New and Updated Features:The following features are new (or have been significantly updated) since version 1.10:Wireshark now uses the Qt application framework. The new UI should provide a significantly better user experience, particularly on Mac OS X and Windows.A more flexible, modular memory manger (wmem) has been added. It was available experimentally in 1.10 but is now mature and has mostly replaced the old API.Expert info is now filterable and now requires a new API.The Windows installer now uninstalls the previous version of Wireshark silently. You can still run the uninstaller manually beforehand if you wish to run it interactively.The "Number" column shows related packets and protocol conversation spans (Qt only).When manipulating packets with editcap using the -C choplen> and/or -s options, it is now possible to also adjust the original frame length using the -L option.You can now pass the -C option to editcap multiple times, which allows you to chop bytes from the beginning of a packet as well as at the end of a packet in a single step.You can now specify an optional offset to the -C option for editcap, which allows you to start chopping from that offset instead of from the absolute packet beginning or end."malformed" display filter has been renamed to "_ws.malformed". A handful of other filters have been given the "_ws." prefix to note they are Wireshark application specific filters and not dissector filters.New Protocol Support:ASTERIX, SEL RTAC (Real Time Automation Controller) EIA-232Serial-Line Dissection, and UDTUpdated Protocol Support:Too many protocols have been updated to list here.New and Updated Capture File Support:Netscaler 2.6, and STANAG 4607
The following vulnerabilities have been fixed:The IEEE 802.15.4 dissector could crash. (Bug 9139)The NBAP dissector could crash. Discovered by Laurent Butti. (Bug 9168)The SIP dissector could crash. (Bug 9228)The OpenWire dissector could go into a large loop. Discovered by Murali. (Bug 9248)The TCP dissector could crash. (Bug 9263)The following bugs have been fixed:new_packet_list: EAP-TLS reassemble does not happen when NEW_PACKET_LIST is toggled. (Bug 5349)TLS decryption fails with XMPP start_tls. (Bug 8871)Wrong Interpretation of GTS starting slot. (Bug 8946)"Follow TCP Stream" shows only the first HTTP req+res. (Bug 9044)The value of SEND_TO_UE in the DIAMETER Gx dictionary for Packet-Filter-Usage AVP is 0 instead of 1. (Bug 9126)Crash then try to delete the same entry (length range) twice. (Bug 9129)Crash if wrong "packet lengths range" entered. (Bug 9130)Bssgp ⇒ SGSN-INVOKE-TRACE use the wrong function… (Bug 9157)Minor correction to dissection of DLR frames in Ethernet/IP dissector. (Bug 9186)WebSphere MQ V7 Bug Fix 8322 TSHM_EBCDIC. (Bug 9198)EDNS0 "Higher bits in extended RCODE" incorrectly decoded in packet-dns.c. (Bug 9199)Files with pcap-ng Simple Packet Blocks can’t be read. (Bug 9200)Bug in RTP dissector if RTP extension is present. (Bug 9204)Improve "eHRPD Indicator" NVSE dissection in 3GPP2 A11 Registration Request. (Bug 9206)"make debian-package" fails, missing wsicon32.xpm. (Bug 9209)Fix typo in MODCOD list of DVB-S2 dissector. (Bug 9218)Ring buffer crash when tshark gets too far behind dumpcap. (Bug 9258)PTP Dissector Wrongfully Reports Malformed Packet. (Bug 9262)Wireshark lua dissector unable to load for media_type=application/octet-stream. (Bug 9296)Wireshark crash when dissecting packet with NTLMSSP. (Bug 9299)Padding in uint64 field in DCERPC protocol wrongly reported. (Bug 9300)DCERPC data_blobs are not correctly dissected when NDR64 encoding is used. (Bug 9301)Multiple PDUs in the same DCERPC packet are not correctly decrypted. (Bug 9302)The tshark summary line doesn’t display the frame number or displays it sporadically. (Bug 9317)Bluetooth: SDP improvements and minor fixes. (Bug 9327)Duplicate IRC header field abbreviation breaks filter (example: irc.response.command). (Bug 9360)Updated Protocol Support:3GPP2 A11, Bluetooth SDP, BSSGP, DCERPC, DCERPC NDR, DCERPC NT, DIAMETER, DNS, DVB-S2, Ethernet, EtherNet/IP, H.225, IEEE 802.15.4, IRC, NBAP, NTLMSSP, OpenWire, PTP, RTP, SIP, TCP, WiMax, and XMPP