Release of the network analyzer Wireshark 4.2

The release of the new stable branch of the network analyzer Wireshark 4.2 has been published. Recall that the project was originally developed under the name Ethereal, but in 2006, due to a conflict with the trademark owner of Ethereal, the developers were forced to rename the project to Wireshark. Wireshark 4.2 is the first release formed under the auspices of the non-profit organization Wireshark Foundation, which will now oversee the project's development. The project's code is distributed under the GPLv2 license.

Key innovations in Wireshark 4.2.0:

  • Improved capabilities related to sorting network packets. For example, in order to accelerate output, only packets visible after applying a filter are now sorted. The user is given the option to interrupt the sorting process.
  • The default sorting in dropdown lists is now based on the time of usage rather than the creation of records.
  • Wireshark and TShark have established correct output generation in UTF-8 encoding. The use of the slice operator on UTF-8 strings now results in the formation of a UTF-8 string rather than a byte array.
  • A new filter has been added to exclude arbitrary byte sequences in packets (@some.field == ), which, for example, can be used to catch invalid UTF-8 strings.
  • The use of arithmetic expressions is allowed in the set filter items.
  • A logical XOR operator has been added.
  • Improvements have been made to the autocomplete features in filters.
  • The ability to search for MAC addresses in the IEEE OUI registry has been added.
  • Configuration files defining manufacturer and service lists have been compiled for faster loading.
  • On the Windows platform, support for a dark theme has been added. An installer for Arm64 architecture has been added for Windows. Compilation for Windows using the MSYS2 toolkit is now possible, as well as cross-compilation in Linux. A new external dependency—SpeexDSP—has been added to the Windows builds (previously the code was built in).
  • Installation files for Linux are now not tied to a location in the file system and use relative paths in RPATH. The directory for extcap plugins has been moved to $HOME/.local/lib/wireshark/extcap (was $XDG_CONFIG_HOME/wireshark/extcap).
  • By default, compilation with Qt6 is provided; to build with Qt5, USE_qt6=OFF must be specified in CMake.
  • Support for Cisco IOS XE 17.x has been added to 'ciscodump'.
  • The interface update interval for traffic capture has been reduced from 500ms to 100ms (can be changed in settings).
  • The design of the Lua console has been changed, now featuring a single common window for input and output.
  • The JSON dissector module has been updated with settings to manage value escaping and display data in the raw format.
  • The IPv6 dissector module now supports displaying semantic details about the address and can parse the APN6 option in HBH (Hop-by-Hop Options Header) and DOH (Destination Options Header) headers.
  • The XML dissector module now includes the ability to display characters according to the encoding specified in the document header or selected by default in settings.
  • The SIP dissector module has been enhanced to specify encoding for displaying SIP message content.
  • For HTTP, chunked data parsing has been implemented in stream reassembly mode.
  • The multimedia type dissector module now supports all MIME types mentioned in RFC 6838 and has removed case sensitivity.
  • Support for the following protocols has been added:
    • HTTP/3,
    • MCTP (Management Component Transport Protocol),
    • BT-Tracker (UDP Tracker Protocol for BitTorrent),
    • ID3v2,
    • Zabbix,
    • Aruba UBT,
    • ASAM Capture Module Protocol (CMP),
    • ATSC Link-Layer Protocol (ALP),
    • DECT DLC protocol layer (DECT-DLC),
    • DECT NWK protocol layer (DECT-NWK),
    • DECT proprietary Mitel OMM/RFP Protocol (AaMiDe),
    • Digital Object Identifier Resolution Protocol (DO-IRP),
    • Discard Protocol,
    • FiRa UWB Controller Interface (UCI),
    • FiveCo’s Register Access Protocol (5CoRAP),
    • Fortinet FortiGate Cluster Protocol (FGCP),
    • GPS L1 C/A LNAV,
    • GSM Radio Link Protocol (RLP),
    • H.224,
    • High Speed Fahrzeugzugang (HSFZ),
    • IEEE 802.1CB (R-TAG),
    • Iperf3,
    • JSON 3GPP,
    • Low Level Signalling (ATSC3 LLS),
    • Matter home automation protocol,
    • Microsoft Delivery Optimization, Multi-Drop Bus (MDB),
    • Non-volatile Memory Express — Management Interface (NVMe-MI) over MCTP,
    • RDP audio output virtual channel Protocol (rdpsnd),
    • RDP clipboard redirection channel Protocol (cliprdr),
    • RDP Program virtual channel Protocol (RAIL),
    • SAP Enqueue Server (SAPEnqueue),
    • SAP GUI (SAPDiag),
    • SAP HANA SQL Command Network Protocol (SAPHDB),
    • SAP Internet Graphic Server (SAP IGS),
    • SAP Message Server (SAPMS),
    • SAP Network Interface (SAPNI),
    • SAP Router (SAPROUTER),
    • SAP Secure Network Connection (SNC),
    • SBAS L1 Navigation Messages (SBAS L1),
    • SINEC AP1 Protocol (SINEC AP),
    • SMPTE ST2110-20 (Uncompressed Active Video),
    • Train Real-Time Data Protocol (TRDP),
    • UBX (u-blox GNSS receivers),
    • UWB UCI Protocol, Video Protocol 9 (VP9),
    • VMware HeartBeat,
    • Windows Delivery Optimization (MS-DO),
    • Z21 LAN Protocol (Z21),
    • ZigBee Direct (ZBD),
    • Zigbee TLV.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster