Thursday, November 19, 2015

Wireshake WPA2-PSK decryption is not working

I have tried many times to decrypt wifi pkt captures using Wireshark without success. I googled extensively but didn't find why the decryption is not working. Finally I think I found how to decrypt wifi captures. The secret is in Edit --> Preferences --> Protocols --> IEEE 802.11

Ignore the protection bit is set to "no" by default. Set that to "Yes - with IV".  As soon as I set this I could see the data pkts.

Also make sure that the pkt capture contains a 4-way handshake.

