Re: Trying to monitor wireless trafic



pedro.forum@xxxxxxxxx schrieb:

If you have a wireless network interface you may set it to promisc
mode, configure the enc key and watch for packets.

You need to set the device into monitor mode.
The analogy between a cable network and a wireless can be described pretty closely:
Ad-hoc:crossover connection between to nodes.
Managed:switched network.
Monitor:similiar to a network with a router (aside from the fact that sending is usually not possible).

Setting the device to monitor mode from managed mode is thus similiar to exchanging a switch with a router. Setting promiscous mode is of course necesarry on top of this to capture packets.
.



Relevant Pages

  • Re: Trying to monitor wireless trafic
    ... I would like to monitor the network trafic on my home wireless network. ... I would like to monitor which computers are connected, what they are doing, etc. ... I tried using Ethereal, but it sees only the packets issued by the computer it's running on, not the packets exhanged between the access point and other computers of the network. ... If youre using ndiswrapper youre probably out of luck, as most windows drivers dont support monitor mode. ...
    (comp.os.linux.networking)
  • Re: Ethernet issue: works one way but not another
    ... packets transmitted, 5 packets received, 0% packet loss ... (This is when connected directly to internet through ... FBSD, I have been working with BSDI at the isp I work for for the last ... As for my network topology, I have an internal network that goes ...
    (freebsd-questions)
  • Re: Update: UDP 770 Potential Worm
    ... > the network immediately after the 'attack', ... were no packets indicating some form of replication. ... I noticed that the UDP ... > of the UDP datagrams is the IP address of the proxy? ...
    (Incidents)
  • Re: IDSIPS that can handle one Gig
    ... especially with 64-byte UDP packets. ... There are plenty of network IPS's ... IDS/IPS devices through use of fragments. ... Find out quickly and easily by testing it with real-world attacks from ...
    (Focus-IDS)
  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)