Release of network analyzer Wireshark 4.6.0.

After a year of development, a release of the new stable branch of the network analyzer Wireshark 4.6 has been published. The program supports over a thousand network protocols and several dozen traffic capture formats. It provides a graphical interface for creating filters, capturing traffic, analyzing saved dumps, and inspecting packets. Advanced features such as reordering of packet sequences, extracting and saving contents of files transmitted using various protocols, VoIP and RTP stream playback, and decryption of IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2 are supported. The project code is distributed under the GPLv2 license.

Key innovations in Wireshark 4.6.0:

  • In the 'Statistics' menu, a 'Plots' mode has been added to the graph section. Unlike the previously available 'I/O Graphs' mode, which displayed histograms reflecting changes in averaged data over time, the 'Plots' mode visualizes the distribution of actual values, highlighting recurring patterns more clearly. Release of network analyzer Wireshark 4.6.0.
  • I/O Graphs have been optimized for display on low-resolution screens. Release of network analyzer Wireshark 4.6.0.
  • Support has been added for compressing captured traffic streams during recording, rather than during rotation of already recorded files. To work with compressible streams in TShark, the '--compress' option can be used.
  • The ability to copy the packet list in HTML format has been added (the 'Edit > Copy > as HTML' option has been included in the menu).
  • An option for manual re-parsing of packets (Redissect Packets) has been added to the 'View' menu, which can be used in case of a change in the encryption key or DNS host associated with IP address.
  • The ability to export X.509 certificates has been implemented using the 'File > Export Objects' menu in Wireshark and the '--export-objects' option in TShark.
  • Support has been added for decrypting NTP packets transmitted using the NTS (Network Time Security) protocol.
  • When decoding MACsec packets, the use of the MKA dissector module is now available.
  • Support for content compressed using the Zstandard algorithm has been added to the HTTP and HTTP/2 traffic dissectors.
  • The 'Follow Stream' dialog has been enhanced with the ability to track MPEG 2 stream identifiers (Transport Stream PID) for extracting audio and video for subsequent playback.
  • Support for the DNP 3 (Distributed Network Protocol 3) has been added in the 'Conversations' and 'Endpoints table' dialogs.
  • Support for marking HTTP2 streams transmitted in 3GPP sessions over 5G network interfaces has been added.
  • On the Linux platform, the ability to use BPF extension filters 'inbound', 'outbound', and 'ifindex', compiled via the 'Compiled Filter' dialog, is provided for traffic capture.
  • The Lua API has added support for Libgcrypt functions for symmetric encryption.
  • Support for decoding RIFF (Resource Interchange File Format) and TTL file formats has been added.
  • Support has been added for the following protocols and formats:
    • Asymmetric Key Packages (AKP),
    • Binary HTTP,
    • BIST TotalView-ITCH (BIST-ITCH),
    • BIST TotalView-OUCH (BIST-OUCH),
    • Bluetooth Android HCI (HCI ANDROID),
    • Bluetooth Intel HCI (HCI INTEL),
    • BPSec COSE Context,
    • BPSec Default SC,
    • Commsignia Capture Protocol (C2P),
    • DECT NR+ (DECT-2020 New Radio),
    • DLMS/COSEM,
    • Ephemeral Diffie-Hellman Over COSE,
    • Identifier-Locator Network Protocol (ILNP),
    • LDA Neo Device trailer (LDA_NEO_TRAILER),
    • Lenbrook Service Discovery Protocol (LSDP),
    • LLC V1,
    • Navitrol (messenger),
    • Network Time Security Key Establishment Protocol (NTS-KE),
    • Ouster VLP-16,
    • Private Line Emulation (PLE),
    • RC V3,
    • RCG,
    • Roughtime,
    • SBAS L5 Navigation Message,
    • SGP.22 GSMA Remote SIM Provisioning (SGP.22),
    • SGP.32 GSMA Remote SIM Provisioning (SGP.32),
    • SICK CoLA,
    • Silabs Debug Channel,
    • Universal Measurement and Calibration Protocol (XCP),
    • USB Picture Transfer Protocol (USB-PTP),
    • VLP-16,
    • vSomeIP Internal Protocol (vSomeIP).
  • For macOS, universal builds have been prepared instead of separate packages for Arm and Intel architectures.
  • In builds for macOS and Windows, the ability to force enable dark or light mode, regardless of system settings, has been implemented. The Qt library in builds for Windows and macOS has been updated to version 6.9.3 (previously shipped was version 6.5.3). Support for AirPcap and WinPcap has been discontinued, and Npcap should be used instead.
  • The libxml2 library has been included as a mandatory dependency.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster