Decrypting using Aircrack-ng

Let's use Aircrack-ng to find the network key. We will type aircrack-ng followed by the PCAP file:

We can see that we got the WEP key with ease. We can use this key to decrypt packets in Wireshark:

We will navigate to Edit... and choose Preferences. Once the dialog box is open, we will choose protocols and scroll down to IEEE 802.11, as shown in the preceding screenshot. Next, we will select the Decryption Keys option and choose Edit, which will populate a separate dialog box, as follows:

We will click the + sign, ...

Get Hands-On Network Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.