Social media buttons


  • 7.5
  • Good
  • 68
  • 7
  • Good
  • Good
Your rating:
Your rating
  1. 0
Free (GPL)
  • Windows 2000
  • Windows XP
  • Windows 2003
  • Windows Vista
  • Windows 7
  • Windows 8
Latest version:
1.10.3 (32 bits) 05/11/13
Last month's downloads:
21.1 MB

Wireshark is fully compatible with:

  • Windows 2000
  • Windows XP
  • Windows 2003
  • Windows Vista
  • Windows 7
  • Windows 8
Wireshark is also compatible with
Wireshark is also available in other platforms

Report software

Thanks for your collaboration!

Oops, something's gone wrong. Try again.

*Required fields


Available languages

  • English


Powerful multi-platform protocol analyzer

Nick Mead

Recent changes

  • Bug Fixes

  • * The following bugs have been fixed:
  • * Wireshark is unresponsive when capturing from named pipes on Windows. (Bug 1759)
  • * Ring buffers are no longer turned on by default when using multiple capture files.

  • New and Updated Features

  • * The following features are new (or have been significantly updated) since version 1.4:
  • * Wireshark can import text dumps, similar to text2pcap.
  • * You can now view Wireshark's dissector tables (for example the TCP port to dissector mappings) from the main window.
  • * TShark can show a specific occurrence of a field when using '-T fields'.
  • * Custom columns can show a specific occurrence of a field.
  • * You can hide columns in the packet list.
  • * Wireshark can now export SMB objects.
  • * dftest and randpkt now have manual pages.
  • * TShark can now display iSCSI service response times.
  • * Dumpcap can now save files with a user-specified group id.
  • * Syntax checking is done for capture filters.
  • * You can display the compiled BPF code for capture filters in the Capture Options dialog.
  • * You can now navigate backwards and forwards through TCP and UDP sessions using Ctrl+, and Ctrl+. .
  • * Packet length is (finally) a default column.
  • * TCP window size is now avaiable both scaled and unscaled. A TCP window scaling graph is available in the GUI.
  • * 802.1q VLAN tags are now shown by the Ethernet II dissector.
  • * Various dissectors now display some UTF-16 strings as proper Unicode including the DCE/RPC and SMB dissectors.
  • * The RTP player now has an option to show the time of day in the graph in addition to the seconds since beginning of capture.
  • * The RTP player now shows why media interruptions occur.
  • * Graphs now save as PNG images by default.
  • * TShark can read and write host name information from and to pcapng-formatted files. Wireshark can read it. TShark can dump host name information via
  • * [-z hosts].
  • * The tshark -z option now uses the

  • [-z ,srt]

  • syntax instead of

  • [-z ,rtt]
  • * for all protocols that support service response time statistics. This syntax now matches Wireshark's syntax for this option.

  • New Protocol Support

  • * ADwin, ADwin-Config, Apache Etch, Aruba PAPI, Babel Routing Protocol, Constrained Application Protocol (COAP), Digium TDMoE, Erlang Distribution Protocol, Ether-S-I/O, FastCGI, Fibre Channel over InfiniBand (FCoIB), Gopher, Gigamon GMHDR, IDMP, Infiniband Socket Direct Protocol (SDP), JSON, LISP Data, MikroTik MAC-Telnet, Mongo Wire Protocol, Network Monitor 802.11 radio header, OPC UA ExtensionObjects, PPI-GEOLOCATION-GPS, ReLOAD, ReLOAD Framing, RSIP, SAMETIME, SCoP, SGSAP, Tektronix Teklink, WAI authentication, Wi-Fi P2P (Wi-Fi Direct)

  • Updated Protocol Support

  • * New and Updated Capture File Support
  • o Apple PacketLogger, Catapult DCT2000, Daintree SNA, Endace ERF, HP OpenVMS TCPTrace, IPFIX (the file format, not the protocol), Lucent/Ascend debug, Microsoft Network Monitor, Network Instruments, TamoSoft CommView

  • Getting Wireshark

  • * Wireshark source code and installation packages are available from

  • Vendor-supplied Packages

  • * Most Linux and Unix vendors supply their own Wireshark packages. You can usually install or upgrade Wireshark using the package management system specific to that platform. A list of third-party packages can be found on the download page on the Wireshark web site.

  • File Locations

  • * Wireshark and TShark look in several different locations for preference files, plugins, SNMP MIBS, and RADIUS dictionaries. These locations vary from platform to platform. You can use About
  • Analyses hundreds of protocols
  • Works across platforms
  • Packets can be viewed in an easy to use GUI
  • Not suitable for amateur network analysis
  • Requires protocol analysis knowledge

"Best used to monitor a network....."

  • 6.0
  • 6.0
  • usability7
  • Stability8
  • Installation7
  • Functionality9
  • Appearance6

.....and NOT your girlfriend! Recently in the news for assisting some bloke to catch his woman cheating, Ethereal is a handy packet sniffer that will capture and decode everything that is going through a network. Why you would want to see what your lady friend is chatting about is totally up to you, but with this tool you can do it pretty easily.

Takes a bit of time to get used to, especially if your on a busy connection. Make good use of the filters and you'll be able to check practically any element of the network traffic whether over a wired connection or a wireless.

  • Records all your network traffic, Lets you see what it's being used for, chat conversations, web pages, passwords, etc.
  • A bit difficult to use effectively. Can catch you cheating. Can be used to find out passwords, or crack a wireless connection

Was this review useful?

25 Apr 2006

What do you think about Wireshark?

Your avatar
All opinions
Free Download Wireshark

Top Downloads: General

  • United States
  • Global
  1. Monitor RS232/422/485 COM ports in network

  2. ...
  3. 13 Wireshark: Powerful multi-platform protocol analyzer Wireshark

Articles Wireshark

Discover alternatives to and add-ons for Wireshark

Alternatives to Wireshark

Wireshark Wireshark

  • 7
  • 7
  • 7.4
  • 7.4

Addons for Wireshark

  • Wireshark doesn’t have any addons yet. Would you recommend any to us? Tell us