How to make Wireshark show http format instead of 802.11 or check if Wireshark is capturing it












0














First of all, this might look like a duplicate from this post, and it kind of is, but at the time writing my rep is not high enough to comment and I was walking in to some issues whilst applying that answer.



I have set up an open WiFi AP (testing-hotspot) and I'm trying to sniff WiFi traffic coming from and going to it.
I connected to it with my phone and loaded up a non secure testing website (just HTTP, no SSL or whatsoever) and filled in a password form.



I expected to see it appear in Wireshark but it didn't. After I did some research regarding my issue I came across the aforementioned question and tried the there given answer, typing http in the filter box with no results, just an empty screen. It does intercept date from the AP because it shows SSID=testing-hotspot. Does anyone know what is causing this and how I can fix this?



--Edit:



I've added a screenshot
added a screenshot



I would like to know how I can see HTTP, TCP, UDP and so forth packets instead of 802.11










share|improve this question





























    0














    First of all, this might look like a duplicate from this post, and it kind of is, but at the time writing my rep is not high enough to comment and I was walking in to some issues whilst applying that answer.



    I have set up an open WiFi AP (testing-hotspot) and I'm trying to sniff WiFi traffic coming from and going to it.
    I connected to it with my phone and loaded up a non secure testing website (just HTTP, no SSL or whatsoever) and filled in a password form.



    I expected to see it appear in Wireshark but it didn't. After I did some research regarding my issue I came across the aforementioned question and tried the there given answer, typing http in the filter box with no results, just an empty screen. It does intercept date from the AP because it shows SSID=testing-hotspot. Does anyone know what is causing this and how I can fix this?



    --Edit:



    I've added a screenshot
    added a screenshot



    I would like to know how I can see HTTP, TCP, UDP and so forth packets instead of 802.11










    share|improve this question



























      0












      0








      0







      First of all, this might look like a duplicate from this post, and it kind of is, but at the time writing my rep is not high enough to comment and I was walking in to some issues whilst applying that answer.



      I have set up an open WiFi AP (testing-hotspot) and I'm trying to sniff WiFi traffic coming from and going to it.
      I connected to it with my phone and loaded up a non secure testing website (just HTTP, no SSL or whatsoever) and filled in a password form.



      I expected to see it appear in Wireshark but it didn't. After I did some research regarding my issue I came across the aforementioned question and tried the there given answer, typing http in the filter box with no results, just an empty screen. It does intercept date from the AP because it shows SSID=testing-hotspot. Does anyone know what is causing this and how I can fix this?



      --Edit:



      I've added a screenshot
      added a screenshot



      I would like to know how I can see HTTP, TCP, UDP and so forth packets instead of 802.11










      share|improve this question















      First of all, this might look like a duplicate from this post, and it kind of is, but at the time writing my rep is not high enough to comment and I was walking in to some issues whilst applying that answer.



      I have set up an open WiFi AP (testing-hotspot) and I'm trying to sniff WiFi traffic coming from and going to it.
      I connected to it with my phone and loaded up a non secure testing website (just HTTP, no SSL or whatsoever) and filled in a password form.



      I expected to see it appear in Wireshark but it didn't. After I did some research regarding my issue I came across the aforementioned question and tried the there given answer, typing http in the filter box with no results, just an empty screen. It does intercept date from the AP because it shows SSID=testing-hotspot. Does anyone know what is causing this and how I can fix this?



      --Edit:



      I've added a screenshot
      added a screenshot



      I would like to know how I can see HTTP, TCP, UDP and so forth packets instead of 802.11







      wireless-networking http wireshark sniffing 802.11






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited Dec 12 at 9:15









      Burgi

      3,84192542




      3,84192542










      asked Dec 8 at 21:58









      Joeri

      12




      12






















          1 Answer
          1






          active

          oldest

          votes


















          0














          Your screenshot only shows beacon frames, not actual data between your phone and the AP.



          So either (1) you are capturing the wrong wifi interface, or (2) you didn't show us the captured non-beacon frames, or (3) your phone wasn't connected to your testing-hotspot, but to some other AP, or (4) your whole setup is in a way that you don't capture data between the phone and the AP.



          Note that you won't see traffic between other clients and the AP on WLAN, so if you are capturing this on a client different from your phone, it is not going to work.



          You either need to capture the traffic on the phone, or on the AP itself. And the AP must be configured to forward the packets to some other network interface, e.g. LAN. If you bridged an WLAN-AP to a WLAN-STATION, you may not see any packets.






          share|improve this answer





















          • Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
            – grawity
            Dec 12 at 10:17











          Your Answer








          StackExchange.ready(function() {
          var channelOptions = {
          tags: "".split(" "),
          id: "3"
          };
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function() {
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled) {
          StackExchange.using("snippets", function() {
          createEditor();
          });
          }
          else {
          createEditor();
          }
          });

          function createEditor() {
          StackExchange.prepareEditor({
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader: {
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          },
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          });


          }
          });














          draft saved

          draft discarded


















          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1381969%2fhow-to-make-wireshark-show-http-format-instead-of-802-11-or-check-if-wireshark-i%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          0














          Your screenshot only shows beacon frames, not actual data between your phone and the AP.



          So either (1) you are capturing the wrong wifi interface, or (2) you didn't show us the captured non-beacon frames, or (3) your phone wasn't connected to your testing-hotspot, but to some other AP, or (4) your whole setup is in a way that you don't capture data between the phone and the AP.



          Note that you won't see traffic between other clients and the AP on WLAN, so if you are capturing this on a client different from your phone, it is not going to work.



          You either need to capture the traffic on the phone, or on the AP itself. And the AP must be configured to forward the packets to some other network interface, e.g. LAN. If you bridged an WLAN-AP to a WLAN-STATION, you may not see any packets.






          share|improve this answer





















          • Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
            – grawity
            Dec 12 at 10:17
















          0














          Your screenshot only shows beacon frames, not actual data between your phone and the AP.



          So either (1) you are capturing the wrong wifi interface, or (2) you didn't show us the captured non-beacon frames, or (3) your phone wasn't connected to your testing-hotspot, but to some other AP, or (4) your whole setup is in a way that you don't capture data between the phone and the AP.



          Note that you won't see traffic between other clients and the AP on WLAN, so if you are capturing this on a client different from your phone, it is not going to work.



          You either need to capture the traffic on the phone, or on the AP itself. And the AP must be configured to forward the packets to some other network interface, e.g. LAN. If you bridged an WLAN-AP to a WLAN-STATION, you may not see any packets.






          share|improve this answer





















          • Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
            – grawity
            Dec 12 at 10:17














          0












          0








          0






          Your screenshot only shows beacon frames, not actual data between your phone and the AP.



          So either (1) you are capturing the wrong wifi interface, or (2) you didn't show us the captured non-beacon frames, or (3) your phone wasn't connected to your testing-hotspot, but to some other AP, or (4) your whole setup is in a way that you don't capture data between the phone and the AP.



          Note that you won't see traffic between other clients and the AP on WLAN, so if you are capturing this on a client different from your phone, it is not going to work.



          You either need to capture the traffic on the phone, or on the AP itself. And the AP must be configured to forward the packets to some other network interface, e.g. LAN. If you bridged an WLAN-AP to a WLAN-STATION, you may not see any packets.






          share|improve this answer












          Your screenshot only shows beacon frames, not actual data between your phone and the AP.



          So either (1) you are capturing the wrong wifi interface, or (2) you didn't show us the captured non-beacon frames, or (3) your phone wasn't connected to your testing-hotspot, but to some other AP, or (4) your whole setup is in a way that you don't capture data between the phone and the AP.



          Note that you won't see traffic between other clients and the AP on WLAN, so if you are capturing this on a client different from your phone, it is not going to work.



          You either need to capture the traffic on the phone, or on the AP itself. And the AP must be configured to forward the packets to some other network interface, e.g. LAN. If you bridged an WLAN-AP to a WLAN-STATION, you may not see any packets.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Dec 12 at 9:34









          dirkt

          9,04231121




          9,04231121












          • Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
            – grawity
            Dec 12 at 10:17


















          • Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
            – grawity
            Dec 12 at 10:17
















          Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
          – grawity
          Dec 12 at 10:17




          Seeing beacon frames usually means monitor mode, which should be able to capture any frame received via radio, even if it's addressed to another device... Or at least it used to be possible with older modes (b/g/n).
          – grawity
          Dec 12 at 10:17


















          draft saved

          draft discarded




















































          Thanks for contributing an answer to Super User!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.





          Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


          Please pay close attention to the following guidance:


          • Please be sure to answer the question. Provide details and share your research!

          But avoid



          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.


          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function () {
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1381969%2fhow-to-make-wireshark-show-http-format-instead-of-802-11-or-check-if-wireshark-i%23new-answer', 'question_page');
          }
          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Plaza Victoria

          Puebla de Zaragoza

          Musa