This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

decrypting WPA2 Traffic of a client

0

Hello,

i'm trying to decrypt the packets of my android-smartphone which is connected to my AP. I setup the wpa-pwd in the decryption settings. The Decryption works with the wireshark example capture file, so i can see the decrypted Packets in that capture.

The Problem is that i only get EAPOL Packets 1,2,3 when i capture the 4 Way Handshake between my smartphone and the AP, but the 4th is Missing. Does Wireshark need all 4 Packets before it starts Decryption? I read that only Packets 1 and 2 are needed for Decryption!? Is it just not decrypting because the fourth Packet is missing?

i'm using wireshark 1.8.1 on Backtrack5. Wifi Card is an Intel 5100agn.

-frank

asked 25 Nov '12, 04:13

frank999's gravatar image

frank999
1112
accept rate: 0%

edited 25 Nov '12, 04:21