Wireshark is a popular open-source network protocol analyzer that is primarily used by security experts and network administrators for several purposes:-
Troubleshooting
Analysis
Development
Education
Its popularity originates from its:-
Robust features
User-friendly interface
Versatility in analyzing network issues
Troubleshooting network issues
All these key factors make Wireshark one of the top choices for several organizations in a multitude of sectors. Besides this, recently, Wireshark Foundation launched version 4.2.0, introducing new updates and features.
What’s new in Wireshark 4.2.0?
Under the Wireshark Foundation, the “Wireshark 4.2.0” is the first major Wireshark release, which brings the following new additions and features:-
Dark mode support on Windows.
A Windows installer for Arm64 has been added.
Packet list sorting has been improved.
Wireshark and TShark are now better about generating valid UTF-8 output.
A new display filter feature for filtering raw bytes has been added.
Display filter autocomplete is smarter about not suggesting invalid syntax.
Tools › MAC Address Blocks can lookup a MAC address in the IEEE OUI registry.
The enterprises, manuf, and services configuration files have been compiled in for improved start-up times.
The installation target no longer installs development headers by default.
The Wireshark installation is relocatable on Linux.
Wireshark can be compiled on Windows using MSYS2.
Wireshark can be cross-compiled for Windows using Linux.
Tools › Browser (SSL Keylog) can launch your web browser with the SSLKEYLOGFILE environment variable set to the appropriate value.
Windows installer file names now have the format Wireshark-<version>-<architecture>.exe.
Here below, we have mentioned all the updated protocol support:-
JSON
IPv6
XML
SIP
HTTP
CFM
New and Updated Codec support
Adaptive Multi-Rate (AMR), if compiled with opencore-amr is the new and updated codec support.
Major API Changes
Here below, we have mentioned all the major API changes:-
Lua function “package.prepend_path” has been removed.
Added reassemble_streaming_data_and_call_subdissector() API for easier reassembly of non-TCP high-level protocol streaming data.
Some of the API now uses C99 types instead of GLib types.
Moreover, the Linux/Unix vendors offer Wireshark packages via platform-specific package management. If you want, then you can find the third-party packages on Wireshark’s download page.
Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.