I have tried many times to decrypt wifi pkt captures using Wireshark without success. I googled extensively but didn't find why the decryption is not working. Finally I think I found how to decrypt wifi captures. The secret is in Edit --> Preferences --> Protocols --> IEEE 802.11
Ignore the protection bit is set to "no" by default. Set that to "Yes - with IV". As soon as I set this I could see the data pkts.
Also make sure that the pkt capture contains a 4-way handshake.
No comments:
Post a Comment