Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-26-2011, 07:29 PM
Aaron Leonard
Guest
 
Posts: n/a
Default Tips on wireless sniffing

We posted some new articles on cisco.com, on the subject of getting a wireless
packet capture. The main focus is to help Cisco customers collect captures so
that we can troubleshoot their problems, but these tips may be generally useful.

https://supportforums.cisco.com/docs/DOC-19232

Please let me know if you see any errors.

Aaron

Reply With Quote
  #2 (permalink)  
Old 10-26-2011, 08:46 PM
miso
Guest
 
Posts: n/a
Default Re: Tips on wireless sniffing

On 10/26/2011 12:29 PM, Aaron Leonard wrote:
> We posted some new articles on cisco.com, on the subject of getting a wireless
> packet capture. The main focus is to help Cisco customers collect captures so
> that we can troubleshoot their problems, but these tips may be generally useful.
>
> https://supportforums.cisco.com/docs/DOC-19232
>
> Please let me know if you see any errors.
>
> Aaron


Technically, isn't a packet sniffer strictly passive? If so, then the
comment about the sniffer using a transmitter doesn't make sense.

No mention of wireshark. Is netmon better?

Reply With Quote
  #3 (permalink)  
Old 10-27-2011, 09:23 PM
Aaron Leonard
Guest
 
Posts: n/a
Default Re: Tips on wireless sniffing

>On 10/26/2011 12:29 PM, Aaron Leonard wrote:
>> We posted some new articles on cisco.com, on the subject of getting a

wireless
>> packet capture. The main focus is to help Cisco customers collect captures

so
>> that we can troubleshoot their problems, but these tips may be generally

useful.
>>
>> https://supportforums.cisco.com/docs/DOC-19232


>Technically, isn't a packet sniffer strictly passive?


Yes.

>If so, then the
>comment about the sniffer using a transmitter doesn't make sense.


If you're referring to 1) in https://supportforums.cisco.com/docs/DOC-19136 -
then that's not quite what it says there. Maybe we could word it better.

>No mention of wireshark. Is netmon better?


OK, let's break this down ...

* Wireshark actually works well in Mac OS X 10.7 to do a wireless sniff, and in
fact our doc https://supportforums.cisco.com/docs/DOC-19212 gives some examples

* Wireshark also can be used in Linux to do a wireless sniff ... we decided not
to document anything in this area however, because there are so many variants of
Linux, not to mention driver issues.

* With Windows, however, Wireshark normally *can't* do a wireless sniff. The
exception is with the AirPcap adapters from Riverbed (nee CACE). (It would be
ideal if Wireshark could be enhanced to hook into the Windows 7 driver API for
promiscuous wireless ... but on the other hand, as Riverbed is a sponsor of
Wireshark's ...)

Thus, when it comes to "free" wireless sniffing in Windows 7, Netmon is the only
game in town. I'm not too thrilled about the user interface, but it does
usually work pretty well (modulo whatever the capabilities of the underlying
adapter may provide.)

Thanks for the feedback.

Aaron

Reply With Quote
  #4 (permalink)  
Old 11-22-2011, 10:26 PM
Axel Hammerschmidt
Guest
 
Posts: n/a
Default Re: Tips on wireless sniffing

Aaron Leonard <Aaron@Cisco.COM> wrote:

> We posted some new articles on cisco.com, on the subject of getting a
> wireless packet capture. The main focus is to help Cisco customers
> collect captures so that we can troubleshoot their problems, but these
> tips may be generally useful.
>
> https://supportforums.cisco.com/docs/DOC-19232
>
> Please let me know if you see any errors.


https://supportforums.cisco.com/docs/DOC-16398

"Note that, even though Netmon 3.4 is supported with XP SP3 and Vista,
it supports wireless sniffing only if running Windows 7."

Netmon (3.4) does monitor mode wireless sniffing fine in (64-bit) Vista
on my Macbook early 2009 with the Apple driver from Boot Camp. Wirelss
card is Broadcom BCM43xx 1.0 (5.10.91.22) - as seen in System Profiler
in OS X 10.5.8.


--
Not him on Facebook

Reply With Quote
  #5 (permalink)  
Old 11-29-2011, 04:57 PM
Aaron Leonard
Guest
 
Posts: n/a
Default Re: Tips on wireless sniffing

>> We posted some new articles on cisco.com, on the subject of getting a
>> wireless packet capture. The main focus is to help Cisco customers
>> collect captures so that we can troubleshoot their problems, but these
>> tips may be generally useful.
>>
>> https://supportforums.cisco.com/docs/DOC-19232
>>
>> Please let me know if you see any errors.

>
>https://supportforums.cisco.com/docs/DOC-16398
>
>"Note that, even though Netmon 3.4 is supported with XP SP3 and Vista,
>it supports wireless sniffing only if running Windows 7."
>
>Netmon (3.4) does monitor mode wireless sniffing fine in (64-bit) Vista
>on my Macbook early 2009 with the Apple driver from Boot Camp. Wirelss
>card is Broadcom BCM43xx 1.0 (5.10.91.22) - as seen in System Profiler
>in OS X 10.5.8.


Thanks Axel; I've updated the article accordingly.

Btw, Netmon 3.4 also captures some interesting wireless packets when
used in non-promiscuous mode, on an adapter in production use. At
least on my Intel 6300, I get to see some beacons and
probe/authentication/association responses from the AP (although
not the probe/authentication/association requests that I'm sending out.)

(Writing that up is on the to-do list.)

Cheers,

Aaron

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Repeater, Access Point, Laptop Triangle of Death (Please Help) TheKingsCrown Network Troubleshooting 11 09-01-2010 09:59 AM
FAQ for AT&T/Cingular Wireless John Navas alt.cellular.cingular 4 02-20-2008 05:06 PM
CFP: Wireless Applications and Computing 2008 natty2006@gmail.com comp.security.misc 0 02-14-2008 03:14 PM
1st PC build bryant.rossiter@gmail.com alt.comp.hardware 28 09-09-2006 09:04 PM
Hacking attempt? MoNk Wireless Networking Discussion 1 05-11-2005 09:21 AM


All times are GMT. The time now is 01:24 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45