Ethereal-users: Re: [Ethereal-users] Sniff wireless on the same machine?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

Date Prev · Date Next · Thread Prev · Thread Next
From: "Jon Baer" <ethereal@xxxxxxxxxxx>
Date: Sun, 31 Aug 2003 18:33:14 -0400
good points (i read somewhere that u could do tx + rx on bsd, not sure if
it's still true) ...

what i would do:

1. just try netstumbler + verify probe responses w/ wep

or

1. download a copy of airopeek nx demo @ wildpackets
(http://www.wildpackets.com/products/airopeek_nx) .. see if u can get it
working w/ ur card first.
2. enable any noisy protocols on ur ap (like plug+play, ddns, etc)

hmm you can probably get that airopeek driver to work directly w/ ethereal
if u try i think ... has anyone done it?

- jon

----- Original Message -----
From: "Guy Harris" <guy@xxxxxxxxxxxx>
To: "Jon Baer" <ethereal@xxxxxxxxxxx>
Cc: <ethereal-users@xxxxxxxxxxxx>
Sent: Sunday, August 31, 2003 8:56 PM
Subject: Re: [Ethereal-users] Sniff wireless on the same machine?


> On Sun, Aug 31, 2003 at 02:35:46PM -0400, Jon Baer wrote:
> > the only real way to do this that i know of is to use a kismet setup to
view
> > the raw packets in monitor mode from ur ssid ...
>
> Unfortunately:
>
> 1) he's running Windows, and according to
>
> http://www.kismetwireless.net/documentation.shtml
>
>    you can't do monitor mode captures native on Win32;
>
> 2) I'm not sure any wireless card under *any* OS can
>    simultaneously run in monitor mode *and* participate in a
>    wireless network - if none can, then a machine can either be
>    a passive monitor-mode sniffer or a participant in a wireless
>    network, but not both, so he can't see whether his machine's
>    traffic is WEP traffic by sniffing from the same machine.
>
> _______________________________________________
> Ethereal-users mailing list
> Ethereal-users@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-users
>