This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Why can’t I see wifi traffic from my andoid phone?

0

Greetings, I am quite new to Wireshark/Linux Kali. I am wondering if, according to my setup, (which I will describe shortly) I should be able to see wifi packets from my cell phone.

I have 4 devices:

  1. Macbook running Kali Linux and Wireshark with TP-LINK TL-WN722N. The interface is set to monitor mode, channel 1 and is associated to my WIFI router's ESSID. I set up the decryption key for 802.11.

  2. Sony Laptop connected to WIFI router on channel 1. In wireshark (running on macbook), once I've captured the handshake I can see everything from this laptop (http, dhcp, tcp etc...) That tells me the decryption key setup is functioning.

  3. My Samsung android phone connected to exact same WIFI on channel 1. Once I capture the handshake, I can only see a few packets but it does not show me much of anything else. Is this normal for android devices? In my research, Ive seen where it was suggested to setup an AP(ie on my macbook) and have the android device connect to it to see the traffic.

  4. Router is an ASUS AC68U, the 2.4 ghz Wireless Mode is set to Auto with b/g protection and 20/40 for the band.

In Wireshark the EAPOL packet (4 of 4)802.11 radio info for my Android shows:

Phy type 802.11b (4)

Channel:1 Freq: 2412 MHZ

and for Sony laptop:

Phy type 802.11g (6)\

Channel: 1 Freq: 2412 MHZ

Why can't I see wifi traffic to/from my android phone? Do I have to set my interface to specifically capture 802.11b to see the packets from my android device? or is this just a red herring.

asked 17 Feb '16, 11:05

jsixpack1's gravatar image

jsixpack1
6113
accept rate: 0%

edited 17 Feb '16, 16:50


One Answer:

0

Your first statement says: "The interface is set to monitor mode, channel 1 and is associated to my WIFI router's ESSID."

That's not how monitor mode works. Once you place your adapter in monitor mode and select a channel, you do not associate to any WLAN. The adapter will capture all the traffic on channel 1.

answered 17 Feb '16, 19:38

Amato_C's gravatar image

Amato_C
1.1k142032
accept rate: 14%

Thank you for the info Amato_C. I appreciate that. Helps increase my knowledge.

(18 Feb '16, 06:30) jsixpack1

If a provided answer solves your problem, please select it as accepted (little check mark). This helps others with similar problems.

(18 Feb '16, 09:11) Amato_C