Decrypting wireless network traffic
Wireshark also facilitates decryption of wireless traffic through embedding a pre-shared key under the 802.11 protocol section. The following screenshot depicts normal wireless traffic being sniffed from a nearby access point:
data:image/s3,"s3://crabby-images/0e43a/0e43a1275ff7dc861a0daf6447804b89764ca51d" alt=""
WLAN traffic before decryption
In order to decrypt the preceding listed packets, we need to configure the IEEE 802.11 section as follows:
- Go to
Edit
|Preferences
, expand theProtocol
section, selectIEEE 802.11
and configure it as follows:
data:image/s3,"s3://crabby-images/c509a/c509a1b38f5f7aabb6880b535102f5e07104a8f9" alt=""
- Click on the
Edit
button next toDecryption Keys
. - Click on
New
and add theWEP/WPA
key to enable decryption. After all the changes have been made, click onOK
:
data:image/s3,"s3://crabby-images/e77bc/e77bce4f06c1c5ce296fab5a791faf4d0cd1fcff" alt=""
Now you will be shown the decrypted traffic as follows:
data:image/s3,"s3://crabby-images/4abbd/4abbd646af5bcad1b7195a12f25f31ac1f5cd447" alt=""
WLAN traffic after decryption