WireShark 1.10.2 description:

WireShark is a Servers & Network software developed by Gerald Combs. After our trial and test, the software is proved to be official, secure and free. Here is the official description for WireShark:

Edit by Marydown: Wireshark is a free network protocol analyzer for Windows and Unix The Ethereal network protocol analyzer has changed its name to Wireshark. The name might be new, but the software is the same. Wireshark's powerful features make it the tool of choice for network troubleshooting, protocol development, and education worldwide.

Wireshark was written by networking experts around the world, and is an example of the power of open source.

Wireshark is used by network professionals around the world for Analysis, troubleshooting, software and protocol development and education.

The program has all of the standard features you would expect in a protocol analyzer, and several features not seen in any other product. Its open source license allows talented experts in the networking community to add enhancements.

New and Updated Features

The following features are new (or have been significantly updated) since version 1.4:

Wireshark is Now distributed as an installation package rather than a drag-installer on OS X. The installer adds a startup item that should make it easier to Capture packets.

Large file (greater than 2 GB) support has been improved.
Wireshark and TShark can import text dumps, Similar to text2pcap.
You can now view Wireshark's dissector tables (for example the TCP port to dissector mappings) from the main window.

Wireshark can export SSL session keys via File→Export→SSL Session Keys...
TShark can show a specific occurrence of a field when using '-T fields'.
Custom columns can show a specific occurrence of a field.

You can hide columns in the packet list.
Wireshark can now export SMB objects.
dftest and randpkt now have manual pages.

TShark can now display iSCSI, ICMP and ICMPv6 service response times.
Dumpcap can now save files with a user-specified group id.
Syntax checking is done for capture filters.

