rdp decryption over ssl

2018-11-23

Rockky gravatar image

I have a piece of software that sends keystrokes over RDP using SendKeys, but currently it isn't working and I want to know why. I have access to both client and server encryption keys, so the plan was to decrypt the session and see what is being sent, and why it fails, but when I go to configure the RSA keys list, I get the following message:

While 'rdp' is a valid dissector filter name, that dissector is not configured to support ssl decryption. If you need to decrypt 'rdp' over ssl, please contact the Wireshark development team.

What are my options here? Can this be achieved?

Thanks for any assistance.

2019-08-23

Cy1337 gravatar image

You should specify tpkt instead of rdp as the underlying protocol. I guess some of the documentation out there is out of date. Please refer to Wireshark Wiki RDP Page for details.

Asked: 2018-11-23

Seen: 1,268 times

Last updated: Aug 23 '19