介绍
Wireshark(前称Ethereal)是一款免费开源的网络嗅探抓包工具,世界上最流行的网络协议分析器!网络封包分析软件的功能是撷取网络封包,并尽可能显示出最为详细的网络封包资料。Wireshark网络抓包工具使用WinPCAP作为接口,直接与网卡进行数据报文交换,可以实时检测网络通讯数据,检测其抓取的网络通讯数据快照文件,通过图形界面浏览这些数据,可以查看网络通讯数据包中每一层的详细内容。它的强大特性:例如包含有强显示过滤器语言和查看TCP会话重构流的能力,支持上百种协议和媒体类型。
软件截图

更新日志
Wireshark 4.6.1 Release Notes
What’s New
Bug Fixes
wnpa-sec-2025-05 BPv7 dissector crash.
wnpa-sec-2025-06 Kafka dissector crash.
The following bugs have been fixed:
L2CAP dissector doesn’t understand retransmission mode.
DNS HIP dissector labels PK algorithm as HIT length.
clang-cl error in "packet-zbee-direct.c".
Writing to an LZ4-compressed output file might fail.
endian.h conflics with libc for building plugins.
TShark crash caused by Lua plugin.
Wireshark stalls for a few seconds when selecting specific messages.
TLS Abbreviated Handshake Using New Session Ticket.
Custom websocket dissector does not run.
WINREG QueryValue triggers dissector bug in packet-dcerpc.c.
Lua: FileHandler causing crash when reading packets.
Apply As Filter for field with FT_NONE and BASE_NONE for a single byte does not use the hex value.
Layout preference Pane 3 problem with selecting Packet Diagram or None.
TCP dissector creates invalid packet diagram.
Too many nested VLAN tags when opening as File Format.
Omnipeek files not working in 4.6.0.
Support UTF-16 strings in the IsoBus dissector for the string operations.
SNMP getBulkRequest request-id does not get filtered for correctly.
Fuzz job issue: fuzz-2025-11-12-12064814316.pcap.
UDP Port 853 (DoQ) should be decoded as QUIC.
What’s New
Bug Fixes
wnpa-sec-2025-05 BPv7 dissector crash.
wnpa-sec-2025-06 Kafka dissector crash.
The following bugs have been fixed:
L2CAP dissector doesn’t understand retransmission mode.
DNS HIP dissector labels PK algorithm as HIT length.
clang-cl error in "packet-zbee-direct.c".
Writing to an LZ4-compressed output file might fail.
endian.h conflics with libc for building plugins.
TShark crash caused by Lua plugin.
Wireshark stalls for a few seconds when selecting specific messages.
TLS Abbreviated Handshake Using New Session Ticket.
Custom websocket dissector does not run.
WINREG QueryValue triggers dissector bug in packet-dcerpc.c.
Lua: FileHandler causing crash when reading packets.
Apply As Filter for field with FT_NONE and BASE_NONE for a single byte does not use the hex value.
Layout preference Pane 3 problem with selecting Packet Diagram or None.
TCP dissector creates invalid packet diagram.
Too many nested VLAN tags when opening as File Format.
Omnipeek files not working in 4.6.0.
Support UTF-16 strings in the IsoBus dissector for the string operations.
SNMP getBulkRequest request-id does not get filtered for correctly.
Fuzz job issue: fuzz-2025-11-12-12064814316.pcap.
UDP Port 853 (DoQ) should be decoded as QUIC.
Puresys纯净系统-软件下载.png)
