Wireshark-users: Re: [Wireshark-users] For Mark

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 2 Dec 2008 11:21:05 -0800

On Dec 2, 2008, at 8:56 AM, Faraz Hasan wrote:

I am using WireShark on Windows. Is there absolutely no way to capture wireless traffic without anything more than a PC connected to the net!

There are ways:

1) make sure your Personal Computer is a PowerBook or MacBook and run OS X on it;

2) if it's not a Mac, run Linux or {Free,Net,Open,DragonFly}BSD on it (you can perhaps also do that if it's a Mac, but it's not necessary);

3) if you have to run Windows, run Windows Vista (or perhaps Windows Server 2008) and use Microsoft Network Monitor 3.1 or later, rather than a WinPcap-based application such as Wireshark.

Further, what are the limitations if AirPcap adaptor is not used?

You probably won't be able to capture traffic other than traffic to and from your machine, and you will only be able to capture data frames, not management or control frames.