Wireshark-dev: Re: [Wireshark-dev] wireless nic is not showing in wireshark

From: Tyson Key <tyson.key@xxxxxxxxx>
Date: Sat, 2 Oct 2010 20:55:00 +0100
Hi Nikhil,

Under Windows 7, the 802.11 interface is simply named "Microsoft" for some unfathomable reason. 

Unfortunately, because WinPCap (and by extension Wireshark) does not utilise the new APIs/mechanisms for capturing raw 802.11 frames that are provided by NDIS 6, you'll only see synthetic Ethernet frames if you capture in "Local Mode"/Station Mode. 

However, it is possible to use Microsoft's Network Monitor 3.4 to capture 802.11 frames (with a poorly-designed, proprietary pseudo-header, of course) to a file that can be read by recent versions of Wireshark; in either Local Mode or Monitor Mode - providing that you're willing to accept various caveats:
  • 802.1X frames from Ad-Hoc networks are seemingly ignored/dropped - although other data and management frames are captured
  • Wireshark cannot currently handle "type 7"/Raw IPv6 frames in NetMon capture files - so some frames may appear to be missing, or your file might not load as you'd expect
  • The capture engine and pseudo-header have a habit of causing management frames to be corrupted or treated as Malformed packets within Wireshark (and I've encountered Beacon frames that have invalid TLV data blobs attached to them post-capture, which were never generated or transmitted)
I hope that helps,

Tyson.

On 2 October 2010 03:20, Nikil Roy <nikhilroy62@xxxxxxxxx> wrote:
hi 

am nikhil, i have an issue with wireshark. am using windows 7 home premium, the other i have installed wireshark and when i started to capture its only showing the Fast Ethernet NIC Wat's the problem. is it the problem with my laptop or something else?  I hope i may get a reply soon.

thank you
Nikhil

--

(¨`·.·´¨) Always
`·.¸(¨`·.·´¨) Keep
(¨`·.·´¨)¸.·´ Smiling!
 `·.¸.·´   With prayer and love
            Nikhil Roy, Muvattupuzha
            nihkilroy62@xxxxxxxxx
             mob:09025523721
            http://www.nikhilroy.110mb.com


___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
            mailto:wireshark-dev-request@xxxxxxxxxxxxx?subject=unsubscribe



--
                                          Fight Internet Censorship! http://www.eff.org
http://vmlemon.wordpress.com | Twitter/FriendFeed/Skype: vmlemon | 00447934365844