This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

With capture filter tcp port https I only seem to capture decrypted HTTP requests when promiscuous mode is enabled. Found the problem by accident and was wondering why this might be.

This question is marked "community wiki".

asked 15 Dec '11, 20:26

kcd's gravatar image

kcd
6113
accept rate: 0%


It might be that you do not receive all HTTPS packets when promiscuous mode is not enabled. Or maybe you started the non-promiscuous trace without restarting the browser, which means you will see only reused ssl sessions, which do not contain the session-key exchange.

permanent link

answered 17 Dec '11, 03:02

SYN-bit's gravatar image

SYN-bit ♦♦
17.1k957245
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×319
×69
×53
×43

question asked: 15 Dec '11, 20:26

question was seen: 2,844 times

last updated: 17 Dec '11, 03:02

p​o​w​e​r​e​d by O​S​Q​A