Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Problems with wireless decryption

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Gerald Combs <gerald@xxxxxxxxxxxxx>
Date: Thu, 06 Dec 2007 13:44:29 -0800

Magee, Owen wrote:
> I'm trying to use the 802.11 wireless decryption features in Wireshark
> without much luck.  We're using Wireshark 0.99.6a on Windows XP with the
> AirPCap Wi-Fi capture card.  It can capture non-encrypted data fine.
> However, I'm trying to decrypt a CCMP/AES/WPA2 encrypted network.  I'm
> seeing a couple of odd behaviors:
> 
> 1.  When I go to the Decryption Keys window and try to add a WPA-PSK
> entry (giving the key explicitly), it doesn't seem to take it.  Once I
> click OK and then go back to the Decryption Keys window, the entry has
> disappeared.

This should be fixed in Wireshark 0.99.7. A prerelease version is available at
http://www.wireshark.org/download/prerelease/wireshark-setup-0.99.7pre2.exe.

> 2.  I switched to using the passphrase and SSID (WPA-PWD), but it does
> not appear to be working.  I'm sure that I have the SSID and the
> passphrase correct, and I'm also sure that I'm capturing the 802.11i key
> exchange as part of the capture.  I'm pinging a device on the Wi-Fi
> network while capturing, but the frames are coming across as some sort
> of LLC frame--it looks like garbage.  In any case, there's definitely no
> ping packet in there.

Are you capturing the key exchange for the session, e.g. does the display filter
"eapol" show any packets? Wireshark won't be able to reconstruct the keys for a
session unless all four key exchange packets are present.

  • References:
    • [Wireshark-users] Problems with wireless decryption
      • From: Magee, Owen
  • Prev by Date: [Wireshark-users] a beginner for setup guide for Win32
  • Next by Date: Re: [Wireshark-users] IEEE 802.11 wpa-pwd seems to break if I add a time reference (using 0.99.6)
  • Previous by thread: [Wireshark-users] Problems with wireless decryption
  • Next by thread: [Wireshark-users] help - write Data to flat file
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation