Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > Sniff and decode wifi packets?

Reply
Thread Tools Display Modes

Sniff and decode wifi packets?

 
 
hman_120@yahoo.com
Guest
Posts: n/a

 
      12-17-2005, 01:17 AM
Hi All
What software can do the following:
-place my wifi card in promiscous mode
-capture all wireless network packets and decode them, presenting the
TCP/IP pieces of it and the payload?

Thanks,
David

 
Reply With Quote
 
 
 
 
David Taylor
Guest
Posts: n/a

 
      12-17-2005, 07:23 AM
> What software can do the following:
> -place my wifi card in promiscous mode
> -capture all wireless network packets and decode them, presenting the
> TCP/IP pieces of it and the payload?


Ethereal on Linux
Airopeek for example on Windows

The first is the free option but you do need a supported card, see the
ethereal website, you didn't say what OS or card.

David.
 
Reply With Quote
 
Jeff Liebermann
Guest
Posts: n/a

 
      12-17-2005, 04:02 PM
On Sat, 17 Dec 2005 08:23:39 GMT, David Taylor <(E-Mail Removed)>
wrote:

>> What software can do the following:
>> -place my wifi card in promiscous mode


Very few drivers for Windoze will put cards in the promiscuous mode.
All the Linux wireless card drivers will do that. That's why most
such sniffing is done with Linux based utilities.

I suggest you download and run one of the Linux LiveCD distributions
that are designed for Wireless. They contain everything you need in
addition to some goodies you probably didn't know you needed.
http://www.remote-exploit.org/index.php/Auditor_main
You boot the cdrom on your laptop, it automagically recognizes the
hardware, and you sniff away merrily. No reformatting and installing
Linux on your laptop hard disk required.

>> -capture all wireless network packets and decode them, presenting the
>> TCP/IP pieces of it and the payload?


Ethereal will capture and decode packets. However, you'll need
something else if you're planning to look at the encrypted contents or
reassemble the packets.

>Ethereal on Linux
>Airopeek for example on Windows


Airopeek SE is $895 plus $300/year support.
Airopeek NX is $2995 plus $675/yr for support.

>The first is the free option but you do need a supported card, see the
>ethereal website, you didn't say what OS or card.


Right. See:
http://www.remote-exploit.org/index....itor_dev_list1
for list of tested wireless cards.

--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
udp packets necessary for wifi connection colorpurple Wireless Networks 1 10-17-2009 09:53 PM
PAP often fails: log decode ? no-toppost@motz.invalid Linux Networking 0 05-04-2009 01:49 PM
Decode PPP-trace please ? news@absamail.co.za Linux Networking 2 08-08-2005 11:22 AM
Strange Sniff ValerioZ Linux Networking 1 10-10-2004 11:01 PM
Need gateway app to sniff all network/wifi traffic Mitchua Wireless Internet 1 05-10-2004 10:54 AM



1 2 3 4 5 6 7 8 9 10 11