Favicon

Wireshark 1.0.2 is now available


I'm proud to announce the release of Wireshark 1.0.2.

What is Wireshark?

   Wireshark is the world's most popular network protocol analyzer.
   It is used for troubleshooting, analysis, development, and
   education.

What's New

  Bug Fixes

   The following vulnerabilities have been fixed. See the security
   advisory for details and a workaround.

     o Wireshark could crash while reassembling packets.

       Versions affected: 0.8.19 to 1.0.1

   The following bugs have been fixed:

     o Dumpcap could crash on some versions of Windows (primarily
       Vista). (Bug 2677)

  New and Updated Features

   There are no new or updated features in this release.

  New Protocol Support
(Continue reading)

Favicon

Wireshark 1.0.1 is now available


I'm proud to announce the release of Wireshark 1.0.1.

What is Wireshark?

   Wireshark is the world's most popular network protocol analyzer.
   It is used for troubleshooting, analysis, development, and
   education.

What's New

  Bug Fixes

   The following vulnerabilities have been fixed. See the security
   advisory for details and a workaround.

     o The GSM SMS dissector could crash.

       Versions affected: 0.99.2 to 1.0.0

     o The PANA and KISMET dissectors could force Wireshark to quit
       unexpectedly.

       Versions affected: 0.99.3 to 1.0.0

     o The RTMPT dissector could crash.

       Versions affected: 0.99.8 to 1.0.0

     o The RMI dissector could disclose system memory. Discovered by
(Continue reading)

Favicon

Wireshark 1.0.1pre1 is now available


Wireshark 1.0.1pre1 is now available for testing. Installers for Windows, OS X,
and source code can be downloaded immediately from

http://www.wireshark.org/download/prerelease/wireshark-setup-1.0.1pre1.exe
http://www.wireshark.org/download/prerelease/wireshark-1.0.1pre1.u3p
http://www.wireshark.org/download/prerelease/WiresharkPortable-1.0.1pre1.paf.exe
http://www.wireshark.org/download/prerelease/Wireshark%201.0.1pre1%20Intel.dmg
http://www.wireshark.org/download/prerelease/wireshark-1.0.1pre1.tar.gz

The Mac OS X installer requires OS X 10.5 on Intel. We hope to provide
support for PPC and earlier OS X releases in the future.

An in-progress list of changes can be found in the release notes at
http://www.wireshark.org/docs/relnotes/wireshark-1.0.1.html.

Please report any problems you find to the wireshark-dev mailing list or
open a ticket at https://bugs.wireshark.org/ .

Barring any problems, version 1.0.1 will be released on Monday, June 30th.

File verification information:

wireshark-setup-1.0.1pre1.exe: 22214924 bytes
MD5(wireshark-setup-1.0.1pre1.exe)= 26671e49880a996d393f6ca3ae8bb475
SHA1(wireshark-setup-1.0.1pre1.exe)= 3bf9035b763458349efc95cc0f6ef5e2084dea9d
RIPEMD160(wireshark-setup-1.0.1pre1.exe)= 9347fab5943569fd62009b07b485cde1d0a2e606

wireshark-1.0.1pre1.u3p: 19986957 bytes
MD5(wireshark-1.0.1pre1.u3p)= acd9cbea7d9bcd238bb2bb691e5872b4
(Continue reading)

Favicon

What is a good average for malformed packets

Hello,

 

I’m in the process of analyzing traffic from our network and I’m coming across some malformed packets.  Before I start going capture crazy.   What is a good (average) of malformed packets on a network?

 

-Albert -

 

_______________________________________________
Wireshark-announce mailing list
Wireshark-announce@...
https://wireshark.org/mailman/listinfo/wireshark-announce
Favicon

Wireshark 1.0 is now available


I'm proud to announce the release of Wireshark 1.0. This is the culmination of
nearly ten years of hard work by a team of brilliant and talented developers. It
is an honor to be able to work with these people.

On behalf of the development team, I would like to thank Wireshark's user
community for all of your enthusiasm and support over the years. Wireshark
development will continue, and we have lots of great features to offer in the
coming years.

What is Wireshark?

   Wireshark is the world's most popular network protocol analyzer.
   It is used for troubleshooting, analysis, development, and
   education.

What's New

  Bug Fixes

   The following vulnerabilities have been fixed. See the security
   advisory for details and a workaround.

     o The X.509sat dissector could crash.

       Versions affected: 0.99.5 to 0.99.8

     o The Roofnet dissector could crash on Windows, Solaris, and
       possibly other platforms.

       Versions affected: 0.99.5 to 0.99.8

     o The LDAP dissector could crash on Windows and possibly other
       platforms.

       Versions affected: 0.99.2 to 0.99.8

     o The SCCP dissector could crash while using the "decode as"
       feature.

       Versions affected: 0.99.6 to 0.99.8

   The following bugs have been fixed:

     o Several SNMP-related bugs have been fixed.

     o Several memory-related bugs have been fixed.

  New and Updated Features

   The following features are new (or have been significantly
   updated) since the last release:

     o The "About" box finally displays version 1.0.

     o Wireshark now supports custom columns.

     o This release includes an experimental Mac OS X package.

  New Protocol Support

   IEEE 802.15.4, Infiniband, Parallel Redundancy Protocol, RedBack
   Lawful Intercept, Xcsl

  Updated Protocol Support

   AFS, ALCAP, ATM, BACapp, CIGI, DCC (renamed from DCCP), DCCP
   (renamed from DCP), DCERPC SPOOLSS, DCERPC NT, DHCP, DirectPlay,
   EtherCAT, FIX, GIOP, GTP, H.248, HTTP, ICMPv6, ICQ, IPv6, ISIS,
   JXTA, NCP, P_Mul, PCAP, PKIX1Explicit, PTP, RADIUS, Roofnet, RTCP,
   RTMPT, RTP, RX, SABP, SCSI OSD, sFlow, SMPP, SNMP, SSCOP, TAPA,
   TIPC, TPNCP, UNISTIM, X.25, X.509sat, XML

  New and Updated Capture File Support

   Hilscher Analyzer

Getting Wireshark

   Wireshark source code and installation packages are available from
   the download page on the main web site.

  Vendor-supplied Packages

   Most Linux and Unix vendors supply their own Wireshark packages.
   You can usually install or upgrade Wireshark using the package
   management system specific to that platform. A list of third-party
   packages can be found on the download page on the Wireshark web
   site.

File Locations

   Wireshark and TShark look in several different locations for
   preference files, plugins, SNMP MIBS, and RADIUS dictionaries.
   These locations vary from platform to platform. You can use
   About->Folders to find the default locations on your system.

Known Problems

   Wireshark may appear offscreen on multi-monitor Windows systems.
   (Bug 553)

   Wireshark might make your system disassociate from a wireless
   network on OS X. (Bug 1315)

   Dumpcap might not quit if Wireshark or TShark crashes. (Bug 1419)

   Wireshark is unable to decrypt WPA group keys. (Bug 1420)

   The BER dissector might infinitely loop. (Bug 1516)

   Wireshark can't dynamically update the packet list. This means
   that host name resolutions above a certain response time threshold
   won't show up in the packet list. (Bug 1605)

   Capture filters aren't applied when capturing from named pipes.
   (Bug 1814)

   Wireshark might freeze when reading from a pipe. (Bug 2082)

   Capturing from named pipes might be delayed on Windows. (Bug 2200)

   Filtering tshark captures with display filters (-R) no longer
   works. (Bug 2234)

   The BOOTP dissector fails to initialize and display some values.
   (Bug 2395)

Getting Help

   Community support is available on the wireshark-users mailing
   list. Subscription information and archives for all of Wireshark's
   mailing lists can be found on the web site.

   Commercial support, training, and development services are
   available from CACE Technologies.

Frequently Asked Questions

   A complete FAQ is available on the Wireshark web site.

Digests

wireshark-1.0.0.tar.bz2: 13413951 bytes
MD5(wireshark-1.0.0.tar.bz2)=90e58c595f082da3ad9390d714f16116
SHA1(wireshark-1.0.0.tar.bz2)=4f53f526359a072665812deca980999bd26e6ab0
RIPEMD160(wireshark-1.0.0.tar.bz2)=12016f80d30954bdc89163958e7d007543b3327e

wireshark-1.0.0.tar.gz: 17043058 bytes
MD5(wireshark-1.0.0.tar.gz)=8c6328955437fd18f9b102a2ea099980
SHA1(wireshark-1.0.0.tar.gz)=d55c999ec333cd109b15ff0de56a2b0296fa1de0
RIPEMD160(wireshark-1.0.0.tar.gz)=e418674d353ffd813e5129a03d359962d33686f2

wireshark-setup-1.0.0.exe: 21713350 bytes
MD5(wireshark-setup-1.0.0.exe)=1a78b6120fc53ab05374eb45556c9c61
SHA1(wireshark-setup-1.0.0.exe)=8d90075ecef04f9f8dbe02ec0e272860dc12c65b
RIPEMD160(wireshark-setup-1.0.0.exe)=9a756353e37c918c89031c2c4e75bf6dd729e106

wireshark-1.0.0.u3p: 19958880 bytes
MD5(wireshark-1.0.0.u3p)=4a477e3cf5ff05fd871aef2865971dea
SHA1(wireshark-1.0.0.u3p)=afc6d8acc1a08dcdd0f9afb3be4f34c2c2d446a5
RIPEMD160(wireshark-1.0.0.u3p)=413c84337dc4fa86ab2d434956a97827743e28ca

WiresharkPortable-1.0.0.paf.exe: 17369822 bytes
MD5(WiresharkPortable-1.0.0.paf.exe)=e371ea1f5797d50e7b6924e81b23cf72
SHA1(WiresharkPortable-1.0.0.paf.exe)=00160cdfda823b3c8aecc473285b1013e0bb15fa
RIPEMD160(WiresharkPortable-1.0.0.paf.exe)=046fb4ad7d91245dfa2648fc8923927c7fc9ba0f

Wireshark 1.0.0 Intel.dmg: 59055412 bytes
MD5(Wireshark 1.0.0 Intel.dmg)=d7039cf4abc49b57ea8267d5458b729c
SHA1(Wireshark 1.0.0 Intel.dmg)=be889b5731cbce3b524bc61c15c51f737fdde4e4
RIPEMD160(Wireshark 1.0.0 Intel.dmg)=33cdbe719197deaf5b70f6f8628f6eb6455415ec

patch-wireshark-0.99.8-to-1.0.0.diff.bz2: 611605 bytes
MD5(patch-wireshark-0.99.8-to-1.0.0.diff.bz2)=1acf7d4ae25ca05ab9465f9f68a5004e
SHA1(patch-wireshark-0.99.8-to-1.0.0.diff.bz2)=b93895c08545c19f70ba71e7615ea410938851b8
RIPEMD160(patch-wireshark-0.99.8-to-1.0.0.diff.bz2)=63a54b8d1294f999a626cf01481001f1b94981c3

Favicon

Wireshark 1.0.0pre1 is now available

Wireshark 1.0.0pre1 is now available for testing. Installers for Windows, OS X,
and source code can be downloaded immediately from

http://www.wireshark.org/download/prerelease/wireshark-setup-1.0.0pre1.exe
http://www.wireshark.org/download/prerelease/wireshark-1.0.0pre1.u3p
http://www.wireshark.org/download/prerelease/WiresharkPortable-1.0.0pre1.paf.exe
http://www.wireshark.org/download/prerelease/Wireshark%201.0.0pre1%20Intel.dmg
http://www.wireshark.org/download/prerelease/wireshark-1.0.0pre1.tar.gz

The Mac OS X installer is new for this release, and is experimental.

An in-progress list of changes can be found in the release notes at
http://www.wireshark.org/docs/relnotes/wireshark-1.0.0.html.

Please report any problems you find to the wireshark-dev mailing list or
open a ticket at http://bugs.wireshark.org/ .

Barring any problems, version 1.0.0 will be released during Sharkfest on Monday,
March 31st.

File verification information:

wireshark-setup-1.0.0pre1.exe: 21714062 bytes
MD5(wireshark-setup-1.0.0pre1.exe)=7f406a60a390f573574965b70251eb42
SHA1(wireshark-setup-1.0.0pre1.exe)=ddf3da6c890114d5af46648e9e7c0fd1a39e19be
RIPEMD160(wireshark-setup-1.0.0pre1.exe)=a3920da1c101a93df2f7de19318c893c39b203b1

wireshark-1.0.0pre1.u3p: 19955689 bytes
MD5(wireshark-1.0.0pre1.u3p)=f0ab6a932165643bfcef64c33e7bdd6e
SHA1(wireshark-1.0.0pre1.u3p)=48a7856a47ce275bcf23d517d54ed8e9a02eca3c
RIPEMD160(wireshark-1.0.0pre1.u3p)=01079112e38c1b06dafa7db5af78e04d882ea1de

WiresharkPortable-1.0.0pre1.paf.exe: 17365814 bytes
MD5(WiresharkPortable-1.0.0pre1.paf.exe)=2b9f6ff0c0772435022d25344754804c
SHA1(WiresharkPortable-1.0.0pre1.paf.exe)=c43755cae61883360902badf159a155833ca0af5
RIPEMD160(WiresharkPortable-1.0.0pre1.paf.exe)=fd264fda26417b1f64c88d5aadef605fc0093ff9

Wireshark 1.0.0pre1 Intel.dmg: 59056532 bytes
MD5(Wireshark 1.0.0pre1 Intel.dmg)=bb4eaf3bb4f03e4d4e568f4235c9054e
SHA1(Wireshark 1.0.0pre1 Intel.dmg)=de962edf9592553ba98a1eb4b762f9eec29a3a6f
RIPEMD160(Wireshark 1.0.0pre1 Intel.dmg)=284f3db752d9920f18ac1eb85919ec981601d2a5

wireshark-1.0.0pre1.tar.gz: 17041792 bytes
MD5(wireshark-1.0.0pre1.tar.gz)=a8b478c8698e5e4afbe1cd8f329f573b
SHA1(wireshark-1.0.0pre1.tar.gz)=815c8f03935da4ef2baa2b088c8a9d49e7d3ab6f
RIPEMD160(wireshark-1.0.0pre1.tar.gz)=d2ac844587987620472c07f25ffded7ea485a7e3

_______________________________________________
Wireshark-announce mailing list
Wireshark-announce <at> wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-announce
Favicon

Wireshark 0.99.8 is now available


I'm proud to announce the release of Wireshark 0.99.8.

Sharkfest Reminder

~   Sharkfest '08 will be held March 31 to April 2 in Los Altos Hills,
~   CA. At Sharkfest you'll have the opportunity to meet many of the
~   people behind Wireshark and WinPcap, and take advantage of the wide
~   variety of courses that will be available. It's an excellent
~   opportunity to learn how to use Wireshark more effectively.

~   In addition to our many talented and knowledgeable presenters, Dr.
~   Vinton Cerf, PhD, Google Vice President and Chief Internet Evangelist
~   will open day 2 of Sharkfest with a talk entitled "Non-discriminatory
~   Network Service."

~   For more information on Sharkfest, visit http://www.cacetech.com or
~   send email to info <at> cacetech.com.

What is Wireshark?

~   Wireshark is the world's most popular network protocol analyzer.
~   It is used for troubleshooting, analysis, development, and
~   education.

What's New

~  Bug Fixes

~   The following vulnerabilities have been fixed. See the security
~   advisory for details and a workaround.

~     o The SCTP dissector could crash.

~       Versions affected: 0.99.5 to 0.99.7

~     o The SNMP dissector could crash.

~       Versions affected: 0.99.6 to 0.99.7

~     o The TFTP dissector could crash Wireshark on Ubuntu 7.10. (This
~       appears to be a bug in the Cairo library on that platform.)
~       Reported by Noam Rathaus.

~       Versions affected: 0.6.0 to 0.99.7

~   The following bugs have been fixed:

~     o Wireshark could crash when saving I/O graphs.

~     o Wireshark could crash when editing table-based preferences.

~     o Wireshark could crash when trying to play RTP streams.

~     o Wireshark could crash when trying to apply a display filter
~       macro.

~     o Wireshark could crash in Turkish and other locales.

~  New and Updated Features

~   The following features are new (or have been significantly
~   updated) since the last release:

~     o You can now have multiple configuration profiles.

~     o Temporary coloring rules have been added, which let you color
~       or filter on a conversation.

~     o I/O graphs have been improved.

~     o Wireshark now has WLAN traffic statistics.

~     o The Wireshark GUI now supports RPCAP.

~     o Conversations and endpoints can now be limited to the current
~       display filter.

~     o Experimental support for the NTAR/PcapNG file format has been
~       added.

~  New Protocol Support

~   AiroPeek Remote Capture, China Mobile Point to Point, Distributed
~   Lock Manager 3, EUTRAN X2 Application Protocol, Fieldbus
~   Foundation, International Passenger Airline Reservation
~   System/Airline Link Control, Microsoft DirectPlay, Path
~   Computation Element communication Protocol, Real Time Messaging
~   Protocol, S1 Application Protocol, Scripting Service Protocol,
~   Societe Internationale de Telecommunications Aeronautiques, Unisys
~   Transmittal System, Wi-fi Protected Setup

~  Updated Protocol Support

~   3G A11, 3GPP, ACN, ACP133, ALCAP, AMR, ANSI A, ANSI IS-637-A, ANSI
~   MAP, ARP, ASAP, AVS WLAN, BACapp, BER, BOOTP, Bluetooth (HCI ACL,
~   HCI CMD, HCI EVT, HCI SCO, L2CAP, SDP), CDP, CFM, CMS, COPS,
~   Camel, Cisco ERSPAN, DAP, DCERPC SPOOLSS, DCERPC, DHCP, DHCPv6,
~   DIAMETER, DMP, DTLS, E.164, EAP, ENIP, ENRP, EtherCAT, Ethernet,
~   FMP, FTAM, GMRP, GRE, GSM MAP, GSM SMS, GSS-API, GTP, Gryphon,
~   H.223, H.225, H.245, H.263, H.264, H.460, HCI H1, HTTP, ICMP, IEEE
~   802.11, IGMP, IPP, ISAKMP, ISUP, JFIF, JPEG, JXTA, Kerberos, LDAP,
~   MP2T, MS MMS, MTP3MG, NBAP, NFS, NHRP, NetFlow, P7, PER, PIM,
~   PKCS12, PPPoE, PTP, P_Mul, Q.932, Quakeworld, RANAP, RMT ALC, RMT
~   LCT, ROS, RPC, RPL, RRC, RTCP, RTP, SCCP, SCTP, SDP, SLL, SMB,
~   SMB2, SMPP, SMTP, SNMP, SRVLOC, SSL, STUN2, T.38, TCAP, TCP, TFTP,
~   TiVoConnect, UCP, UDP-Lite, USB, VLAN, WBXML, X.411, X.420,
~   X.509if, X.509sat

~  New and Updated Capture File Support

~   Catapult DCT2000, DBS Etherwatch, NTAR/PcapNG, TamoSoft CommView,
~   Visual Networks

Getting Wireshark

~   The source code and Windows installer can be downloaded immediately
~   from http://www.wireshark.org/download/ .

~  Vendor-supplied Packages

~   Most Linux and Unix vendors supply their own Wireshark packages.
~   You can usually install or upgrade Wireshark using the package
~   management system specific to that platform. A list of third-party
~   packages can be found on the download page on the Wireshark web
~   site.

File Locations

~   Wireshark and TShark look in several different locations for
~   preference files, plugins, MIBS, and RADIUS dictionaries. These
~   locations vary from platform to platform. You can use
~   About->Folders to find the default locations on your system.

Known Problems

~   The Filter button is nonfunctional in the file dialogs under
~   Windows. (Bug 942)

Getting Help

~   Community support is available on the wireshark-users mailing
~   list. Subscription information and archives for all of Wireshark's
~   mailing lists can be found on the web site.

~   Commercial support, training, and development services are
~   available from CACE Technologies.

Frequently Asked Questions

~   A complete FAQ is available on the Wireshark web site.

Digests

wireshark-0.99.8.tar.bz2: 13243168 bytes
MD5(wireshark-0.99.8.tar.bz2)=5e6af49273c9a588ba3abd92a8423136
SHA1(wireshark-0.99.8.tar.bz2)=a33c7fd8d73bcbf843d3e3a96fd44489212c51e5
RIPEMD160(wireshark-0.99.8.tar.bz2)=3d7a4fdd9e2c9b9abaa0c9fe0c3e76fa86ec9aea

wireshark-0.99.8.tar.gz: 16822076 bytes
MD5(wireshark-0.99.8.tar.gz)=417305db903357c7567b789c86283986
SHA1(wireshark-0.99.8.tar.gz)=4ddee2c03d8a6cfd374cc624f9613ecb2a2e427f
RIPEMD160(wireshark-0.99.8.tar.gz)=2de136f381eeba8de60c2d04afeadd41b51bb353

wireshark-setup-0.99.8.exe: 21292294 bytes
MD5(wireshark-setup-0.99.8.exe)=2a7c6c9167518a98bbad51da3f1bc9bb
SHA1(wireshark-setup-0.99.8.exe)=ee3cd533f4db7e62c1b432c335ab82b8f3e541a4
RIPEMD160(wireshark-setup-0.99.8.exe)=e09f23db50a51ac9eaa16aaaad5bdf0dee36ed08

wireshark-0.99.8.u3p: 19621285 bytes
MD5(wireshark-0.99.8.u3p)=b50c9ae24fcde5aee3ea90886a7e12de
SHA1(wireshark-0.99.8.u3p)=a279f0bd955177c1491ba8332d4b2190df83724c
RIPEMD160(wireshark-0.99.8.u3p)=8ddd90aabee49dabf5caba89a87b0ea557dc6c88

WiresharkPortable-0.99.8.paf.exe: 17029359 bytes
MD5(WiresharkPortable-0.99.8.paf.exe)=b79f61af42fd6be360fc02ae572d6b13
SHA1(WiresharkPortable-0.99.8.paf.exe)=c23d5c4bbf529cffeaea9dbe6c4cf5238aff15c2
RIPEMD160(WiresharkPortable-0.99.8.paf.exe)=32a0a6ef31e708308f48fbcdb95cc2b6eacfb86c

patch-wireshark-0.99.7-to-0.99.8.diff.bz2: 1339189 bytes
MD5(patch-wireshark-0.99.7-to-0.99.8.diff.bz2)=4257cac4d4b8f0e52929409e4597dc06
SHA1(patch-wireshark-0.99.7-to-0.99.8.diff.bz2)=e605a85ad534288582a4a208505fa882abcbb739
RIPEMD160(patch-wireshark-0.99.7-to-0.99.8.diff.bz2)=63414e442f1dcafe5b45f79d72436444b9ea258c

Favicon

Vint Cerf to speak at Sharkfest

We are excited to announce that Dr. Vinton Cerf, PhD, Google Vice President and
Chief Internet Evangelist will open day 2 of Sharkfest with a talk entitled
"Non-discriminatory Network Service." Dr. Cerf is considered by many to be the
father of the Internet. When he's not giving talks on matters that will affect
the Internet for decades to come (such as network neutrality), he works with
NASA on the Interplanetary Internet standard.

For more information on Sharkfest and to register, please visit
http://www.cacetech.com/SHARKFEST.08/

_______________________________________________
Wireshark-announce mailing list
Wireshark-announce <at> wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-announce
Favicon

Wireshark 0.99.8pre1 is now available


Wireshark 0.99.8pre1 is now available for testing. Windows installers
and source code can be downloaded immediately from

http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.8pre1.exe
http://www.wireshark.org/download/prerelease/wireshark-0.99.8pre1.u3p
http://www.wireshark.org/download/prerelease/WiresharkPortable-0.99.8pre1.paf.exe
http://www.wireshark.org/download/prerelease/wireshark-0.99.8pre1.tar.gz

This release adds many bug fixes and new features.  An in-progress list
of changes can be found in the release notes at
http://www.wireshark.org/docs/relnotes/wireshark-0.99.8.html .

Please report any problems you find to the wireshark-dev mailing list or
open a ticket at http://bugs.wireshark.org/ .

Barring any problems, the final release will be out on Monday, February
25th.

File verification information:

wireshark-setup-0.99.8pre1.exe: 21284062 bytes
MD5(wireshark-setup-0.99.8pre1.exe)=b44c651b600f9f7e7a4a9d7a5095219b
SHA1(wireshark-setup-0.99.8pre1.exe)=0788693e4e1f7223533ed25b73781790f62957e4
RIPEMD160(wireshark-setup-0.99.8pre1.exe)=adba8fc817bef8776928e67d2035b9d887dcb1ac

wireshark-0.99.8pre1.u3p: 19609638 bytes
MD5(wireshark-0.99.8pre1.u3p)=30c8611c05d1d34a26d91d72eabf522a
SHA1(wireshark-0.99.8pre1.u3p)=ab3f27739fc2244d4b72b213725a15982df5fbd4
RIPEMD160(wireshark-0.99.8pre1.u3p)=174643ee0835522c0d25275946a9b4e8dd945067

WiresharkPortable-0.99.8pre1.paf.exe: 17021795 bytes
MD5(WiresharkPortable-0.99.8pre1.paf.exe)=60ec1c9ee633d1bf81c6901f83ba7f4c
SHA1(WiresharkPortable-0.99.8pre1.paf.exe)=f6b1eeee055db39b3addc6aef1b4dd6aab621a0b
RIPEMD160(WiresharkPortable-0.99.8pre1.paf.exe)=0b11f1c88e1544a6b7fb78f729e99e7df66a5f41

wireshark-0.99.8pre1.tar.gz: 16815173 bytes
MD5(wireshark-0.99.8pre1.tar.gz)=62d1462c17bf8a0cde06a1ccb7d839a2
SHA1(wireshark-0.99.8pre1.tar.gz)=4c46569f3d3112792f14b6e5a99997d6a25eb9f0
RIPEMD160(wireshark-0.99.8pre1.tar.gz)=86655c294ccb3f550f5f904e00c9d978ec1f3546

Favicon

Wireshark 0.99.7 is now available

I'm proud to announce the release of Wireshark 0.99.7. I'm also proud to
announce Sharkfest '08, the first-ever Wireshark users and developers
conference, and SharkNet, an enterprise maintenance and support program for
Wireshark.

Shameless Promotion

    Sharkfest '08 will be held March 31 to April 2 in Los Altos Hills,
    CA. At Sharkfest you'll have the opportunity to meet many of the
    people behind Wireshark and WinPcap, and take advantage of the wide
    variety of courses that will be available. It's an excellent
    opportunity to learn how to use Wireshark more effectively.

    SharkNet provides a guaranteed response time for Wireshark support
    issues, development assistance, discounts on Wireshark University
    courses, and many other features.

    For more information on Sharkfest and SharkNet, visit
    http://www.cacetech.com or send email to info <at> cacetech.com.

What is Wireshark?

   Wireshark is the world's most popular network protocol analyzer.
   It is used for troubleshooting, analysis, development, and
   education.

What's New

  Bug Fixes

   The following vulnerabilities have been fixed. See the security
   advisory for details and a workaround.

     o Wireshark could crash when reading an MP3 file.

       Versions affected: 0.99.6

     o Beyond Security discovered that Wireshark could loop
       excessively while reading a malformed DNP packet.

       Versions affected: 0.10.12 to 0.99.6

     o Stefan Esser discovered a buffer overflow in the SSL
       dissector.

       Versions affected: 0.99.0 to 0.99.6

     o The ANSI MAP dissector could be susceptible to a buffer
       overflow on some platforms.

       Versions affected: 0.99.5 to 0.99.6

     o The Firebird/Interbase dissector could go into an infinite
       loop or crash.

       Versions affected: 0.99.6

     o The NCP dissector could cause a crash.

       Versions affected: 0.99.6

     o The HTTP dissector could crash on some systems while decoding
       chunked messages.

       Versions affected: 0.10.14 to 0.99.6

     o The MEGACO dissector could enter a large loop and consume
       system resources.

       Versions affected: 0.9.14 to 0.99.6

     o The DCP ETSI dissector could enter a large loop and consume
       system resources.

       Versions affected: 0.99.6

     o Fabiodds discovered a buffer overflow in the iSeries (OS/400)
       Communication trace file parser.

       Versions affected: 0.99.0 to 0.99.6

     o The PPP dissector could overflow a buffer.

       Versions affected: 0.99.6

     o The Bluetooth SDP dissector could go into an infinite loop.

       Versions affected: 0.99.2 to 0.99.6

     o A malformed RPC Portmap packet could cause a crash.

       Versions affected: 0.8.16 to 0.99.6

     o The IPv6 dissector could loop excessively.

       Versions affected: 0.99.6

     o The USB dissector could loop excessively or crash.

       Versions affected: 0.99.6

     o The SMB dissector could crash.

       Versions affected: 0.99.6

     o The RPL dissector could go into an infinite loop.

       Versions affected: 0.9.8 to 0.99.6

     o The WiMAX dissector could crash due to unaligned access on
       some platforms.

       Versions affected: 0.99.6

     o The CIP dissector could attempt to allocate a huge amount of
       memory and crash.

       Versions affected: 0.9.14 to 0.99.6

   The following bugs have been fixed:

     o Handling of non-ASCII file names and paths has been improved.

     o Wireshark could crash while editing a coloring rule or a UAT
       table.

     o The display filter code could crash while bitwise ANDing an
       IPv4 address.

  New and Updated Features

   The following features are new (or have been significantly
   updated) since the last release:

     o Most of the capture code has been moved out of the GUI, which
       means that Wireshark no longer needs to be run as root.

     o Many display filter names have been cleaned up. If your
       favorite display filter just went missing, please consult the
       display filter reference to find out where it ended up.

     o You can now filter directly on SNMP OIDs.

     o IO graphs have more display options, and you can now export
       graphs.

     o You can now follow UDP streams in addition to TCP and SSL
       streams.

     o You can now disable coloring rules without deleting them.

     o Main window toolbar buttons are now available even when the
       window is small.

     o The version of WinPcap that ships with the Windows installers
       has been updated to 4.0.2.

     o The Windows installers now include a "services" file, which
       maps port numbers to names.

     o The Windows installer now enables npf.sys by default under
       Vista. Wireshark will print a warning at startup if npf.sys
       isn't loaded under Vista.

     o Optimizations have been applied in some places to make
       Wireshark start up and run faster.

  New Protocol Support

   ANSI TCAP, application/xcap-error (MIME type), CFM, DPNSS,
   EtherCAT, ETSI e2/e4, H.282, H.460, H.501, IEEE 802.1ad and
   802.1ah, IMF (RFC 2822), RSL, SABP, T.125, TNEF, TPNCP, UNISTIM,
   Wake on LAN, WiMAX ASN Control Plane, X.224,

  Updated Protocol Support

   3Com XNS, 3G A11, ACN, ACP123, ACSE, AIM, ANSI IS-637-A, ANSI MAP,
   Armagetronad, BACapp, BACnet, BER, BFD, BGP, Bluetooth, CAMEL,
   CDT, CFM, CIP, Cisco ERSPAN, CLNP, CMIP, CMS, COPS, CTDB, DCCP,
   DCERPC ATSVC, DCERPC PNIO, DCERPC SAMR, DCERPC, DCOM CBA-ACCO, DCP
   ETSI, DEC DNA, DFS, DHCP/BOOTP, DHCPv6, DIAMETER, DISP, DMP, DNP,
   DNS, DOP, DTLS, DUA, eDonkey, ELSM, ESL, Ethernet, FC ELS, FC,
   FCOE, FTAM, FTP, GDSDB, GIOP, GPRS-LLC, GSM A, GSM MAP, GTP, HSRP,
   HTTP, IAX2, ICMPv6, IEEE 802.11, INAP, IP, IPMI, IPv6, ISAKMP,
   ISIS, iSNS, ISUP, IUUP, JXTA, K12, Kerberos, L2TP, LAPD, LDAP,
   LINX, LPD, LWAPP, MEGACO, MIKEY, MIME Multipart, MMS, MP2T, MPEG
   PES, MPEG, MTP2, MySQL, NBAP, NetFlow, nettl, NFS, NSIP, OSPF,
   P_MUL, PANA, PER, PKCS#12, PMIPv6, PN-PTCP, PN-RT, PPI, PPPoE,
   PRES, PROFINET, PTP, Q.932 ROS, Q.932, QSIG, Radiotap, RADIUS,
   RANAP, RNSAP, ROS, RTCP, RTP, RTSE, RTSP, SCCP, SCTP, SDP,
   SIGCOMP, SIP, Slow Protocols, SMB, SMPP, SMTP, SNDCP, SNMP, SRP,
   SSL, STANAG 4406, STUN2, TCAP, TCP, text/media, TIPC, ULP, UMA,
   UMTS FP, V5UA, VNC, WiMAX M2M, WiMAX, WLCCP, X.411, X.420, X.509
   SAT, XML,

  New and Updated Capture File Support

   Catapult DCT 2000, Endace ERF, Juniper NetScreen snoop, Visual
   Networks, Windows Sniffer (NetXRay)

Getting Wireshark

   Wireshark source code and installation packages are available from
   the download page on the main web site.

  Vendor-supplied Packages

   Most Linux and Unix vendors supply their own Wireshark packages.
   You can usually install or upgrade Wireshark using the package
   management system specific to that platform. A list of third-party
   packages can be found on the download page on the Wireshark web
   site.

File Locations

   Wireshark and TShark look in several different locations for
   preference files, plugins, SNMP MIBS, and RADIUS dictionaries.
   These locations vary from platform to platform. You can use
   About->Folders to find the default locations on your system.

Known Problems

   Saving to the currently-open file doesn't work under Windows. (Bug
   2080)

   The Filter button is nonfunctional in the file dialogs under
   Windows. (Bug 942)

   GTK+ 2.x renders white text on 8-bit displays under Windows. You
   can work around this by installing the GTK+ 1.2 version of
   Wireshark or by increasing your display depth to 15 bits or more.

Getting Help

   Community support is available on the wireshark-users mailing
   list. Subscription information and archives for all of Wireshark's
   mailing lists can be found on the web site.

   Commercial support, training, and development services are
   available from CACE Technologies.

Frequently Asked Questions

   A complete FAQ is available on the Wireshark web site.

References

   Visible links
   . http://www.wireshark.org/security/wnpa-sec-2007-02.html
   . http://www.wireshark.org/docs/dfref/
   . http://www.wireshark.org/download.html
   . http://www.wireshark.org/download.html#otherplat
   . http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2080
   . http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=942
   . http://bugzilla.gnome.org/show_bug.cgi?id=438652
   . http://www.wireshark.org/lists/
   . http://www.cacetech.com/
   . http://www.wireshark.org/faq.html
_______________________________________________
Wireshark-announce mailing list
Wireshark-announce <at> wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-announce
Favicon

Wireshark 0.99.7pre2 is now available


Wireshark 0.99.7pre2 is now available for testing.  Source code and a
Windows installer can be downloaded immediately from

http://www.wireshark.org/download/prerelease/wireshark-0.99.7pre2.tar.gz
http://www.wireshark.org/download/prerelease/wireshark-0.99.7pre2.u3p
http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.7pre2.exe

This release adds many bug fixes and new features.  An in-progress list
of changes can be found in the release notes at
http://www.wireshark.org/docs/relnotes/wireshark-0.99.7.html .

Please report any problems you find to the wireshark-dev mailing list or
open a ticket at http://bugs.wireshark.org/ .

Barring any problems, the final release should be out around December 5.

File verification information:

MD5(wireshark-0.99.7pre2.tar.gz)=3a607338aa222a13fd5208434cae3b6d
SHA1(wireshark-0.99.7pre2.tar.gz)=14288efaeded47043d635c8395643e4e0256190e
RIPEMD160(wireshark-0.99.7pre2.tar.gz)=3049f2e99d2871ae7a12dbb1ecbdceab351f9e06

wireshark-0.99.7pre2.u3p: 26184452 bytes
MD5(wireshark-0.99.7pre2.u3p)=29bc7bf45c421bd145f27f9221eee5c3
SHA1(wireshark-0.99.7pre2.u3p)=cd1ccaea5b9cf037c67c9c46979c239576eadc1a
RIPEMD160(wireshark-0.99.7pre2.u3p)=31756e49562bbd7523d1e4addf4de98ba8fac460

wireshark-setup-0.99.7pre2.exe: 21104206 bytes
MD5(wireshark-setup-0.99.7pre2.exe)=8cd9d3559584853f85d707e91058f5be
SHA1(wireshark-setup-0.99.7pre2.exe)=e8271e321f09db5e887668c9dc81db25d3c483b6
RIPEMD160(wireshark-setup-0.99.7pre2.exe)=c629d50994dcf020c029a10b3d50e4cb53b90558

Gmane