Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] WPA decryption failing

From: "Soh Kam Yung" <sohkamyung@xxxxxxxxx>
Date: Tue, 22 May 2007 09:14:59 +0800
On 5/22/07, Bob Carlson <rjc@xxxxxxxxxx> wrote:
I have version 0.99.5 with AirPcap 2.0. The WPA and WPA2 PSK decryption
does not seem to work. I have checked and double checked that the keys are
correct. I have tried with and without the SSIDs entered. The passphrases
have been entered into the Decryption Keys dialog as WPA-PWD. I have
captured the complete association and EAPOL key exchange. The Enable
Decryption box is checked under IEEE 802.11. There are 2 SSIDs and 2
passphrases. 2 clients connect to each SSID. There is no indication of any
error, the packets are just not decrypted.

Am I missing something? Does this feature not work yet?

Cheers, Bob


Decrypting the WPA pairwise keys should work in that version of Wireshark.

Take a look at (http://wiki.wireshark.org/HowToDecrypt802.11?highlight=%28CategoryHowTo%29)
and try to decrypt the sample capture provided on that page.  You can
also compare the setup against yours to see what might be causing the
problem on your end.

Regards,
Kam-Yung
--
Soh Kam Yung
my delicious links: (http://del.icio.us/SohKamYung)
my simpy links: (http://www.simpy.com/user/kysoh/links)