The protocol analyzer Wireshark has released a new version today. Here is the list of the new features available in version 1.4.0.

From Wireshark:

The following features are new (or have been significantly updated) since version 1.2:

  1. The packet list internals have been rewritten and are now more efficient.
  2. Columns are easier to use. You can add a protocol field as a column by right-clicking on its packet detail item, and you can adjust some column preferences by right-clicking the column header.
  3. Preliminary Python scripting support has been added.
  4. Many memory leaks have been fixed.
  5. Wireshark 1.4 does not support Windows 2000. Please use Wireshark 1.2 or 1.0 on those systems.
  6. Packets can now be ignored (excluded from dissection), similar to the way they can be marked.
  7. Manual IP address resolution is now supported.
  8. Columns with seconds can now be displayed as hours, minutes and seconds.
  9. You can now set the capture buffer size on UNIX and Linux if you have libpcap 1.0.0 or greater.
  10. TShark no longer needs elevated privileges on UNIX or Linux to list interfaces. Only dumpcap requires privileges now.
  11. Wireshark and TShark can enable 802.11 monitor mode directly if you have libpcap 1.0.0 or greater.
  12. You can play RTP streams directly from the RTP Analysis window.
  13. Capinfos and editcap now respectively support time order checking and forcing.
  14. Wireshark now has a “jump to timestamp” command-line option.
  15. You can open JPEG files directly in Wireshark.

Release Notes

(Image used under CC from Allan Lee)

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.