Wireshark mailing list archives

Re: Wishlist Request: 802.11 GTK Decryption


From: Jouni Malinen <jkmalinen () gmail com>
Date: Fri, 12 Nov 2010 02:02:27 +0200

On Fri, Nov 12, 2010 at 1:49 AM, Anthony Murabito
<anthony.murabito () gmail com> wrote:
Thanks so much for the reply & info. Can you point me in the direction of
the external tools than can perform the decryption?

airdecap-ng (part of aircrack-ng) would be one option. I'm working on
more generic IEEE 802.11 protocol analyzer (wlantest, in the
hostap.git tree with hostapd/wpa_supplicant) that can also do this
(though, it is still in early enough state of not having any
documentation available yet). With either program, you can feed in a
pcap file with encrypted frames and some information about the key
(e.g., passphrase for WPA2-Personal network) and get another pcap file
with decrypted frames as the output.

- Jouni
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: