So I stumbled upon something interesting, when I try to connect to my AP with a wrong password from my phone it generates Message 1/4 and 2/4, so far nothing new and i know these are not enough to crack with but yesterday i was able to generate 3/4 and 4/4, whats wierd is that i had wireshark and airodump on and only wireshark captured 3/4 and 4/4, take a look tell me what you think:
the AP in question is Sagemcom.