This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have set up my network card into monitor mode and I have connected to my WPA2 encrypted network. I have another computer with a wireless network card that is also connected to the same network.

I want to capture HTTP data from that computer and everytime I load a webpage from that computer, my other computer with Wireshark on seems to capture some data, but the source is my Netgear router and the protocol is LLC.

I once succeeded to capture the data from my other computer, but I fail now. I have also set the WPA-PSK decryption keys in Wireshark.

What am I doing wrong?

EDIT: I can mention that if I turn of the encryption, it all works perfect, but when encryption is enabled, then it cannot read the data.

asked 26 Jan '11, 11:10

Rox's gravatar image

Rox
217810
accept rate: 0%

edited 26 Jan '11, 11:20


WPA decryption only works if you captured all the way from the start of the WPA session. So you need to start the capture first and then turn on the wireless adapter on the system you would like to monitor.

permanent link

answered 26 Jan '11, 11:32

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

But if I turn off the wireless adapter, then Wireshark cannot find the interface to make the capture on, right?

This is the procedure:

I have two computers, let´s call them "A" and "B". Computer "A" is the one with Wireshark installed.

Borth A and B are disconnected from the network. On A, I run "ifconfig wlan0 up" and then start the capturing session on Wireshark. Then I connect A to the network.

So far B is still disconnected from the network, so when A is capturing on the network, I connect B to it.

In wireshark, I can see two EAPOL packets when connecting computer B ("msg 1/4" and "msg 3/4", where are "msg 2/4" and "msg 4/4"???), but nothing is decrypted. I have added a decryption key in Wireshark.

What is wrong?

permanent link

answered 27 Jan '11, 09:18

Rox's gravatar image

Rox
217810
accept rate: 0%

edited 27 Jan '11, 09:36

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×293
×248
×36

question asked: 26 Jan '11, 11:10

question was seen: 8,431 times

last updated: 27 Jan '11, 09:36

p​o​w​e​r​e​d by O​S​Q​A