If you like network monitoring you’ll know the race is on between MS’s Netmon 3.3 and our trusted wireshark. And as sure as MS released it’s latest and greatest, wireshark is preparing for their next release.
And you will not be disappointed ;-)
Version 1.2 of wireshark is now in pre-release so lets have a quick look at the new features by reviewing the release notes.
New and Updated Features
- Wireshark has a spiffy new start page. => looks nice for the GUI lovers
-
A 64-bit Windows (x64) installer is now provided. => if i need to explain this you should not be reading this article
-
Support for the c-ares resolver library has been added. It has many advantages over ADNS. => c-ares is a C library that performs DNS requests and name resolves asynchronously. I can’t tell you yet why it’s better as stated by the wireshark guys and to be honest i’m not a big fan of doing DNS lookup during traces but from time to time it can be nice.
-
Many new protocol dissectors and capture file formats have been added (see below for a complete list).
-
Macintosh OS X support has been improved. => cool :-p
-
GeoIP database lookups. => Does what it says, links geographical info to ip addresses
to get this working you need to download the geoip database off of http://www.maxmind.com/app/ip-locate

point wireshark to the geoip datbase files in the preference > nameresolution tab
enable the geoip in the protocol preferences
head out to statistics > endpoints and you should see the country / city / … attributes fill
-
Improved Postscript® print output.
-
The preference handling code is now much smarter about changes.
-
Support for Pcap-ng, the next-generation capture file format. => this is the follow up ofr the open pcap standard and allow a more flexible and rich saving of capture files. One of the great features in adding comments like we have come to love in netmon. As of today however this format is not yet supported by netmon so for people like me using both tools for the best of both worlds we are still stuck with pcap.
http://www.winpcap.org/ntar/draft/PCAP-DumpFileFormat.html
-
Support for process information correlation via IPFIX.
-
Column widths are now saved. => finally!!!
-
The last used configuration profile is now saved. => fianally!!!
-
Protocol preferences are changeable from the packet details context menu.
-
Support for IP packet comparison.
-
GTK1 is no longer supported. (Yes, this is a feature.)
-
Official Windows packages are now built using Microsoft Visual C++ 2008 SP1.
New Protocol Support
Anything in Anything Protocol, ATM PW, N-to-one Cell Mode, B.A.T.M.A.N. Layer 3 Protocol, BACnet MS/TP, BSS LCS Assistance Protocol, Canon BJNP, CESoPSN basic NxDS0 mode (no RTP support), Charging ASE, Cimetrics MS/TP, DECT Protocol, Digital Private Signalling System No 1 Link Layer, DOCSIS Mac Domain Description, DOCSIS Registration Request Multipart, DOCSIS Registration Response Multipart, DOCSIS Synchronisation Message, E100 Encapsulation, EHS, Enhanced Variable Rate Codec, Ethernet Global Data, Ethernet PW, Exchange 2003 Directory Request For Response, Far End Failure Detection, FCoE Initialization Protocol, GOOSE, GPEF, GPRS Tunneling Protocol V2, GSM A-I/F COMMON, GSM A-I/F GPRS Mobility and Session Management, GSM SACCH, GSM Um Interface, HDLC PW, FR port mode (no CW), HDLC-like framing for PPP, IEC 60870-5-104,Apci, IEC 60870-5-104,Asdu, IEEE 802.15.4 Low-Rate Wireless PAN non-ASK PHY, IEEE C37.118 Synchrophasor Protocol, Intelligent Platform Management Interface (Session Wrapper), Inter-Integrated Circuit, Internal TDM, IPSICTL, ISMACryp Protocol, iWARP Direct Data Placement and Remote Direct Memory Access Protocol, iWARP Marker Protocol data unit Aligned framing, Kontiki Delivery Protocol, LANforge Traffic Generator, Layer 1 Event Messages, Lb-I/F BSSMAP LE, LeCroy VICP, Link Access Procedure, Channel Dm (LAPDm), Local Download Sharing Service, LTE Radio Resource Control (RRC) protocol, MAC-LTE, Memcache Protocol, Mesh Header, MP4V-ES, Nasdaq TotalView-ITCH, Nasdaq-SoupTCP version 2.0, NAT Port Mapping Protocol, Netdump Protocol, Non-Access-Stratum (NAS)PDU, PacketLogger, Paltalk Messenger Protocol, PDCP-LTE, PW Associated Channel Header, PW Ethernet Control Word, PW Frame Relay DLCI Control Word, PW MPLS Control Word (generic/preferred), Real-Time Publish-Subscribe Wire Protocol 2.x, Remote Packet Capture, RLC-LTE, SAToP (no RTP support), SERCOS III V1.1, SIMULCRYPT Protocol, Subnetwork Dependent Convergence Protocol XID, Teamspeak2 Protocol, TTEthernet, TTEthernet Protocol Control Frame, Turbocell Aggregate Data, Turbocell Header, TURN Channel, Unreliable Multicast Inter-ORB Protocol, VCDU, Wave Short Message Protocol(IEEE P1609.3), Wireless Access Station Session Protocol, Wireshark Expert Info, World of Warcraft, Xpress Transport Protocol, ZigBee Application Framework, ZigBee Application Support Layer, ZigBee Device Profile, ZigBee Encapsulation Protocol, ZigBee Network Layer, Zipped Inter-ORB Protocol, ZRTP