Wireshark(前称Ethereal)是一个网络封包分析软件。网络封包分析软件的功能是撷取网络封包,并尽可能显示出最为详细的网络封包资料。
网络封包分析软件的功能可想像成 "电工技师使用电表来量测电流、电压、电阻" 的工作 - 只是将场景移植到网络上,并将电线替换成网络线。在过去,网络封包分析软件是非常昂贵,或是专门属于营利用的软件。Ethereal的出现改变了这一切。在GNUGPL通用许可证的保障范围底下,使用者可以以免费的代价取得软件与其源代码,并拥有针对其源代码修改及客制化的权利。Ethereal是目前全世界最广泛的网络封包分析软件之一。
Wireshark是免费的网络协议检测程序,支持Unix,Windows。让您经由程序抓取运行的网站的相关资讯,包括每一封包流向及其内容、资讯可依操作系统语系看出,方便查看、监控TCP session动态等等。
更新日志:
The following vulnerabilities have been fixed. See the security advisory for details and a workaround.
The NFS dissector could crash on Windows. (Bug 5209)
Versions affected: 1.4.0 to 1.4.4.
The X.509if dissector could crash. (Bug 5754, Bug 5793)
Versions affected: 1.2.0 to 1.2.15 and 1.4.0 to 1.4.4.
Paul Makowski from SEI/CERT discovered that the DECT dissector could overflow a buffer. He verified that this could allow remote code execution on many platforms.
Versions affected: 1.4.0 to 1.4.4.
The following bugs have been fixed:
Cygwin make fails after updating to bash v 4.1.9.2
Export HTTP > All - System Appears Hung (but isn't). (Bug 1671)
Some HTTP responses don't decode with TCP reassembly on. (Bug 3785)
Wireshark crashes when cancelling a large sort operation. (Bug 5189)
Wireshark crashes if SSL preferences RSA key is actually a DSA key. (Bug 5662)
tshark incorrectly calculates TCP stream for some syn packets. (Bug 5743)
Wireshark not able to decode the PPP frame in a sflow (RFC3176) flow sample packet because Wireshark incorrectly read the protocol in PPP frame header. (Bug 5746)
Mysql protocol dissector: all fields should be little endian. (Bug 5759)
Error when opening snoop from Juniper SSG-140. (Bug 5762)
svnversion: command not found. (Bug 5798)
capinfos: #ifdef HAVE_LIBGCRYPT block includes a line too many. (Bug 5803)
Value of TCP segment data cannot be copied. (Bug 5811)
proto_field_is_referenced() is not exported in libwireshark.dll. (Bug 5816)
Wireshark ver. 1.4.4 not displayed "Granted QoS" field in a A11 packet. (Bug 5822)
下载地址:
Windows Installer (32-bit) Windows Installer (64-bit) Windows U3 (32-bit) Windows PortableApps (32-bit) OS X 1
0.5 (Leopard) Intel 32-bit .dmg OS X 10.6 (Snow Leopard) Intel 64-bit .dmg OS X 10.5 (Leopard) PPC 32-bit .dmg Source Code