Networking Forums

Networking Forums > Computer Networking > Linux Networking > Trying to monitor wireless trafic

Reply
Thread Tools Display Modes

Trying to monitor wireless trafic

 
 
Philippe Perrin
Guest
Posts: n/a

 
      12-27-2007, 09:09 PM
Hello all

I would like to monitor the network trafic on my home wireless network.
I would like to monitor which computers are connected, what they are
doing, etc. Actually the same as I could do if I were using Ethereal
from a router. My wireless network is protected with a WPA key, which I
know of course.
I tried using Ethereal, but it sees only the packets issued by the
computer it's running on, not the packets exhanged between the access
point and other computers of the network.

Is there any way I can see/capture packets on a WPA-protected network,
knowing the key???

Thanks,
Philippe
 
Reply With Quote
 
 
 
 
Syren Baran
Guest
Posts: n/a

 
      12-31-2007, 12:15 AM
Philippe Perrin schrieb:
> Hello all
>
> I would like to monitor the network trafic on my home wireless network.
> I would like to monitor which computers are connected, what they are
> doing, etc. Actually the same as I could do if I were using Ethereal
> from a router. My wireless network is protected with a WPA key, which I
> know of course.
> I tried using Ethereal, but it sees only the packets issued by the
> computer it's running on, not the packets exhanged between the access
> point and other computers of the network.
>
> Is there any way I can see/capture packets on a WPA-protected network,
> knowing the key???

You dont need the key to capture the packets.
You need to change the mode of your wireless card to monitor mode.
You´ll obviously still need some tool to decrypt the captured packets
with your key. If youre using ndiswrapper youre probably out of luck, as
most (to my knowledge) windows drivers dont support monitor mode.
If you can set the mode via iwconfig <device> mode monitor
Ethereal/Wireshark will display the raw packets from other devices as
you cant send in monitor mode.
>
> Thanks,
> Philippe

 
Reply With Quote
 
pedro.forum@gmail.com
Guest
Posts: n/a

 
      12-31-2007, 04:01 PM
On Dec 27, 8:09 pm, Philippe Perrin <philippeper...@yahoo.com> wrote:
> I tried using Ethereal, but it sees only the packets issued by the
> computer it's running on, not the packets exhanged between the access
> point and other computers of the network.


At which computer are you running Wireshark?
Is this computer connected via a wireless network interface?

> Is there any way I can see/capture packets on a WPA-protected network,
> knowing the key???


If you have a wireless network interface you may set it to promisc
mode, configure the enc key and watch for packets.

 
Reply With Quote
 
Syren Baran
Guest
Posts: n/a

 
      12-31-2007, 07:58 PM
(E-Mail Removed) schrieb:

> If you have a wireless network interface you may set it to promisc
> mode, configure the enc key and watch for packets.
>

You need to set the device into monitor mode.
The analogy between a cable network and a wireless can be described
pretty closely:
Ad-hoc:crossover connection between to nodes.
Managed:switched network.
Monitor:similiar to a network with a router (aside from the fact that
sending is usually not possible).

Setting the device to monitor mode from managed mode is thus similiar to
exchanging a switch with a router. Setting promiscous mode is of course
necesarry on top of this to capture packets.
 
Reply With Quote
 
Philippe Perrin
Guest
Posts: n/a

 
      01-01-2008, 08:50 PM
All riht thanks Syren and Pedro. Will work on it when I get back home.
WIll post again if I need more help!

Philippe

Philippe Perrin a écrit :
> Hello all
>
> I would like to monitor the network trafic on my home wireless network.
> I would like to monitor which computers are connected, what they are
> doing, etc. Actually the same as I could do if I were using Ethereal
> from a router. My wireless network is protected with a WPA key, which I
> know of course.
> I tried using Ethereal, but it sees only the packets issued by the
> computer it's running on, not the packets exhanged between the access
> point and other computers of the network.
>
> Is there any way I can see/capture packets on a WPA-protected network,
> knowing the key???
>
> Thanks,
> Philippe

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
route wan trafic to wireless adapter; lan through wired G. Leavitt Wireless Networks 5 04-30-2009 03:21 PM
Trafic Controler and DSMARK antares.pt@gmail.com Linux Networking 0 05-21-2008 11:11 PM
Active Directory trafic over WAN Thinkpad21 Windows Networking 7 02-02-2008 08:01 PM
trafic shaping interupts samba korgman Linux Networking 5 08-08-2006 08:57 PM
trafic control Steffo Wireless Internet 2 10-23-2005 10:40 AM



1 2 3 4 5 6 7 8 9 10 11