Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] 802.11 frame data not decoded

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 10 Aug 2006 18:20:07 -0700


On Aug 10, 2006, at 5:43 PM, Soh Kam Yung wrote:

Steve,

According to the capture, the data is protected:

=====
[...]
        Flags: 0x41
            DS status: Frame from STA to DS via an AP (To DS: 1 From
DS: 0) (0x01)
            .... .0.. = More Fragments: This is the last fragment
            .... 0... = Retry: Frame is not being retransmitted
            ...0 .... = PWR MGT: STA will stay up
            ..0. .... = More Data: No data buffered
            .1.. .... = Protected flag: Data is protected
            0... .... = Order flag: Not strictly ordered
[...]
=====

You may need to setup the WEP key in Wireshark first to decrypt the data packet.

...except that he said

I checked
the data section by hand and it appears that it is indeed a DHCP
request message (as I expected). This problem affects all non-
management packets in my dump file.

so perhaps the "protected" bit setting is bogus.


  • References:
    • [Wireshark-users] 802.11 frame data not decoded
      • From: Steve Magoun
    • Re: [Wireshark-users] 802.11 frame data not decoded
      • From: Soh Kam Yung
  • Prev by Date: Re: [Wireshark-users] 802.11 frame data not decoded
  • Next by Date: Re: [Wireshark-users] 802.11 frame data not decoded
  • Previous by thread: Re: [Wireshark-users] 802.11 frame data not decoded
  • Next by thread: Re: [Wireshark-users] 802.11 frame data not decoded
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation