Wireshark-bugs: [Wireshark-bugs] [Bug 12024] IEEE802.11 FCS issue preventing WPA decryption
Comment # 4
on bug 12024
from Alexander Wetzel
Disclaimer:
I have only a crude understanding how 802.11 works on the Layer-1 and I'm only
really familiar with the 802.11 decryption code in wireshark. So I may be off
here...
That said I strongly suspect that the sniffer (card) is not able to capture the
frames correctly due to an unsupported encoding the AP is using.
Something like the AP using 802.11ac for encoding and the sniffer only supports
802.11bgn.
They are using quite different data rates already and I would expect something
like that when the STA is using a 802.11bgn coding but supports 802.11ac.
And I thing a 802.11bgn card would not be able to set the correct flags in the
radiotab header...
With the filter "wlan.fcs_bad == 1 && not wlan.ta == c4:27:95:bf:c1:a9" you see
quite some other stations with broken FCS, somehow supporting that thesis.
I disabled the encryption for that.
Try forcing the AP (or the client) to 802.11g, I suspect that will "fix" the
capture.
You are receiving this mail because:
- You are watching all bug changes.