Router Charts

Click for Router Charts

Router Ranker

Click for Router Ranker

NAS Charts

Click for NAS Charts

NAS Ranker

Click for NAS Ranker

More Tools

Click for More Tools

Wireless How To

Finding the Four-way Handshake

To make sure we captured a authentication handshake, we can use the network protocol analyzer Wireshark (formerly Ethereal). Wireshark allows us to view packet contents and sort by type of packet captured to pull out the WPA handshake.

Open up Wireshark (Backtrack > Privilege Escalation > Sniffers) and open the Kismet capture "dump" file (Kismet-<date>.dump) to view all the captured packets. The WPA four-way handshake uses the Extensible Authentication Protocol over LAN (EAPoL).

Using Wireshark, we can filter the captured packets to display only EAPoL packets by entering "eapol" in the filter field (Figure 7).

EAPoL filter applied to captured packets

Figure 7: EAPoL filter applied to captured packets

Here, we're basically looking for four packets that alternate source, client-AP-client-AP (I've highlighted them in red in Figure 7).

Now that we've confirmed that we've captured a four-way handshake it's time to perform the crack.

More Wireless

Featured Sponsors

Top Ranked Routers

Support Us!

If you like what we do and want to thank us, just buy something on Amazon. We'll get a small commission on anything you buy. Thanks!

Over In The Forums

Which file system should be used for attaching a USB drive to my ASUS RT-AC88U router - FAT32 or NTFS.Thank you
Hi Guys,Well dramas galore with this router that I love so much.Updated the router to latest Merlin Firmware - then was told to manually turn off / on...
Hi,The QoS rules are applied in order (https://www.asus.com/support/faq/1010951/#User-defined QoS rules), is there anyway to change the order of the r...
I am trying to setup custom dhcp using dnsmasq for my wireless guest networks (RT87U / Firmware:380.66).i have a startup script that works for the 2.4...
Trying to do something like this:But AP Mode disables a lot of the settings I would need and trying to setup PropNet-AP in Router Mode gave me all sor...

Don't Miss These

  • 1
  • 2
  • 3