Decryping WPA2 WLAN traffic in Wireshark












0














I have trouble decryping WPA2 WLAN traffic in Wireshark.



I've done research and followed all advises I could possibly find and still cannot decrypt it. There are of course plenty of variables, but I strongly believe I covered all of them, and yet I'm still missing out something.



Basically, all I can view is Probs, Beacons, Null function (No data) and QoS Null function (No data). I connect to the network with my phone and start randomly browsing and can clearly see my traffic is going in Wireshark, but it only Null function (No data) packets.



I've made sure I added [password]:[ssid] to 802.11 and enabled decryption. Always have long streams and full EAPOLs when capturing the traffic and tried on three different wifi cards (Alfa, TP-link & Intel). I have most up to Kali distribution and latest Wireshark version, and tried on someone else pcaps and Wireshark decrypted it successfully.



The only thing I can think of causing this is the driver.



Please help.










share|improve this question






















  • Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
    – Ankur Aggarwal
    Nov 23 '18 at 10:21






  • 1




    The question is off-topic anyway, since it is not a programming question.
    – DavidW
    Nov 23 '18 at 17:04










  • What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
    – Christopher Maynard
    Dec 4 '18 at 16:33
















0














I have trouble decryping WPA2 WLAN traffic in Wireshark.



I've done research and followed all advises I could possibly find and still cannot decrypt it. There are of course plenty of variables, but I strongly believe I covered all of them, and yet I'm still missing out something.



Basically, all I can view is Probs, Beacons, Null function (No data) and QoS Null function (No data). I connect to the network with my phone and start randomly browsing and can clearly see my traffic is going in Wireshark, but it only Null function (No data) packets.



I've made sure I added [password]:[ssid] to 802.11 and enabled decryption. Always have long streams and full EAPOLs when capturing the traffic and tried on three different wifi cards (Alfa, TP-link & Intel). I have most up to Kali distribution and latest Wireshark version, and tried on someone else pcaps and Wireshark decrypted it successfully.



The only thing I can think of causing this is the driver.



Please help.










share|improve this question






















  • Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
    – Ankur Aggarwal
    Nov 23 '18 at 10:21






  • 1




    The question is off-topic anyway, since it is not a programming question.
    – DavidW
    Nov 23 '18 at 17:04










  • What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
    – Christopher Maynard
    Dec 4 '18 at 16:33














0












0








0







I have trouble decryping WPA2 WLAN traffic in Wireshark.



I've done research and followed all advises I could possibly find and still cannot decrypt it. There are of course plenty of variables, but I strongly believe I covered all of them, and yet I'm still missing out something.



Basically, all I can view is Probs, Beacons, Null function (No data) and QoS Null function (No data). I connect to the network with my phone and start randomly browsing and can clearly see my traffic is going in Wireshark, but it only Null function (No data) packets.



I've made sure I added [password]:[ssid] to 802.11 and enabled decryption. Always have long streams and full EAPOLs when capturing the traffic and tried on three different wifi cards (Alfa, TP-link & Intel). I have most up to Kali distribution and latest Wireshark version, and tried on someone else pcaps and Wireshark decrypted it successfully.



The only thing I can think of causing this is the driver.



Please help.










share|improve this question













I have trouble decryping WPA2 WLAN traffic in Wireshark.



I've done research and followed all advises I could possibly find and still cannot decrypt it. There are of course plenty of variables, but I strongly believe I covered all of them, and yet I'm still missing out something.



Basically, all I can view is Probs, Beacons, Null function (No data) and QoS Null function (No data). I connect to the network with my phone and start randomly browsing and can clearly see my traffic is going in Wireshark, but it only Null function (No data) packets.



I've made sure I added [password]:[ssid] to 802.11 and enabled decryption. Always have long streams and full EAPOLs when capturing the traffic and tried on three different wifi cards (Alfa, TP-link & Intel). I have most up to Kali distribution and latest Wireshark version, and tried on someone else pcaps and Wireshark decrypted it successfully.



The only thing I can think of causing this is the driver.



Please help.







encryption wireshark pcap network-traffic 802.11






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Nov 23 '18 at 10:15









EKreger

1




1












  • Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
    – Ankur Aggarwal
    Nov 23 '18 at 10:21






  • 1




    The question is off-topic anyway, since it is not a programming question.
    – DavidW
    Nov 23 '18 at 17:04










  • What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
    – Christopher Maynard
    Dec 4 '18 at 16:33


















  • Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
    – Ankur Aggarwal
    Nov 23 '18 at 10:21






  • 1




    The question is off-topic anyway, since it is not a programming question.
    – DavidW
    Nov 23 '18 at 17:04










  • What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
    – Christopher Maynard
    Dec 4 '18 at 16:33
















Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
– Ankur Aggarwal
Nov 23 '18 at 10:21




Hi, please go through How to ask a good question? . You should post all the things you tried, maybe along with screenshots.
– Ankur Aggarwal
Nov 23 '18 at 10:21




1




1




The question is off-topic anyway, since it is not a programming question.
– DavidW
Nov 23 '18 at 17:04




The question is off-topic anyway, since it is not a programming question.
– DavidW
Nov 23 '18 at 17:04












What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
– Christopher Maynard
Dec 4 '18 at 16:33




What version of Wireshark are you using, and on what platform? It can often be very helpful to provide Wireshark's "Help -> About Wireshark" information when reporting problems. Anyway, if you're not running the very latest version, you could try upgrading it to see if there might have been any bug fixes affecting you. You might even try one of the latest automated builds from wireshark.org/download/automated. And in case you haven't visited these sites yet, see also wiki.wireshark.org/CaptureSetup/WLAN and wiki.wireshark.org/Wi-Fi.
– Christopher Maynard
Dec 4 '18 at 16:33












0






active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53444719%2fdecryping-wpa2-wlan-traffic-in-wireshark%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.





Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


Please pay close attention to the following guidance:


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53444719%2fdecryping-wpa2-wlan-traffic-in-wireshark%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Catalogne

Violoncelliste

Héron pourpré