Koll på din trafik med Wireshark

Koll på din trafik med Wireshark

Koll på din trafik med Wireshark

Wireshark är ett programför att analysera din trafik (Network protocol) och det är ett program som nästan är standard i vissa tester och inom vissa branscher.

Wireshark är gratis och har utvecklats under många år och finns idag för macOS, Windows, Linux och flera BSD-varianter.

Wireshark is one of the world’s foremost network protocol analyzers, and is the standard in many parts of the industry. It is the continuation of a project that started in 1998. Hundreds of developers around the world have contributed to it, and it it still under active development.

Wireshark has a rich feature set which includes the following:

Standard three-pane packet browser
Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
Multi-interface: Along with a standard GUI, Wireshark includes TShark, a text-mode analyzer which is useful for remote capture, analysis, and scripting
The most powerful display filters in the industry
VoIP analysis
Live capture and offline analysis are supported
Read/write many different capture file formats: tcpdump (libpcap), NAI’s Sniffer (compressed and uncompressed), Sniffer Pro, NetXray, Sun snoop and atmsnoop, Shomiti/Finisar Surveyor, AIX’s iptrace, Microsoft’s Network Monitor, Novell’s LANalyzer, RADCOM’s WAN/LAN Analyzer, HP-UX nettl, i4btrace from the ISDN4BSD project, Cisco Secure IDS iplog, the pppd log (pppdump-format), the AG Group’s/WildPacket’s EtherPeek/TokenPeek/AiroPeek, Visual Networks’ Visual UpTime and many others
Capture files compressed with gzip can be decompressed on the fly
Hundreds of protocols are supported, with more being added all the time
Coloring rules can be applied to the packet list, which eases analysis
What’s New

What’s New

Version 2.4.2:

Bug Fixes:
  • [1]wnpa-sec-2017-42 BT ATT dissector crash ([2]Bug 14049) [3]CVE-2017-15192
  • [4]wnpa-sec-2017-43 MBIM dissector crash ([5]Bug 14056) [6]CVE-2017-15193
  • [7]wnpa-sec-2017-44 DMP dissector crash ([8]Bug 14068) [9]CVE-2017-15191
  • [10]wnpa-sec-2017-45 RTSP dissector crash ([11]Bug 14077) [12]CVE-2017-15190
  • [13]wnpa-sec-2017-46 DOCSIS infinite loop ([14]Bug 14080) [15]CVE-2017-15189
  • Wireshark crash when end capturing with ”Update list of packets in real-time” option off. ([16]Bug 13024)
  • Diameter service response time statistics broken in 2.2.4. ([17]Bug 13442)
  • Sequence number isn’t shown as the X axis in TCP Stream Graph – RTT. ([18]Bug 13740)
  • Using an SSL subdissector will cause SSL data to not be decoded (related to reassembly of application data). ([19]Bug 13885)
  • Wireshark 2.4.0 doesn’t build with Qt 4.8. ([20]Bug 13909)
  • Some Infiniband Connect Req fields are not decoded correctly. ([21]Bug 13997)
  • Voip Flow Sequence button crash. ([22]Bug 14010)
  • wireshark-2.4.1/epan/dissectors/packet-dmp.c:1034: sanity check in wrong place ?. ([23]Bug 14016)
  • wireshark-2.4.1/ui/qt/tcp_stream_dialog.cpp:1206: sanity check in odd place ?. ([24]Bug 14017)
  • [oss-fuzz] ASAN: 232 byte(s) leaked in 4 allocation(s). ([25]Bug 14025)
  • [oss-fuzz] ASAN: 47 byte(s) leaked in 1 allocation(s). ([26]Bug 14032)
  • Own interface toolbar logger dialog for each log command. ([27]Bug 14033)
  • Wireshark crashes when dissecting DOCSIS REGRSPMP which contains UCD. ([28]Bug 14038)
  • Broken installation instructions for Visual Studio Community Edition. ([29]Bug 14039)
  • RTP Analysis ”save as CSV” saves twice the forward stream, if two streams are selected. ([30]Bug 14040)
  • VWR file read ends early with vwr: Invalid data length 0. ([31]Bug 14051)
  • reordercap fails with segmentation fault 11 on MacOS. ([32]Bug 14055)
  • Cannot Apply Bitmask to Long Unsigned. ([33]Bug 14063)
  • text2pcap since version 2.4 aborts when there are no arguments. ([34]Bug 14082)
  • gtpprime: Missing in frame.protocols. ([35]Bug 14083)
  • HTTP dissector believes ICY response is a request. ([36]Bug 14091)
Updated Protocol Support:
  • 6LoWPAN, Bluetooth, BOOTP/DHCP, BT ATT, BT LE, DCERPC, DMP, DOCSIS, EPL, GTP, H.248, HTTP, InfiniBand, MBIM, RPC, RTSP, SSL, and WSP
New and Updated Capture File Support:
  • Ixia IxVeriWave

Requirements

  • Intel, 64-bit processor
  • OS X 10.6 or later
  • X11 or XQuartz

 

Wireshark

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.