Re: [PEN-TEST] wireless LAN traffic sniffing

From: Frank Knobbe (FKnobbeat_private)
Date: Sat Apr 28 2001 - 18:51:43 PDT

  • Next message: Felix Huber: "Re: [PEN-TEST] RPC enumeration"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    > -----Original Message-----
    > From: Jacob Ansari
    > Sent: Friday, April 27, 2001 9:26 PM
    >
    >      Maybe I'm really missing something, but I can't seem to
    > get my 3com
    > AirConnect wlan pcmcia card to operate in promiscuous mode.
    > This is on w2k
    > pro and winnt4 (sp6a).  Couldn't get the Linksys WPC11 card to work
    > in promiscuous mode either.
    
    Jacob,
    
    as far as I know, there are only two wireless network cards that
    support promiscuous mode. One of them if the Cisco 340 (formerly an
    Aironet product). If these cards are switched into promiscuous mode
    by something like tcpdump, it takes usually a reset/restart of the
    NIC or laptop to be able to send again (in normal mode). There are
    some wireless sniffing products that will handle it correctly and
    switch back without much ado. AiroPeek from WildPackets and the
    Sniffer Wireless from NAI are two of them.
    
    I had initially the same problem like you (had a Linksys card and
    AP), and exchanged the Linksys card against the Cisco 340. Not just
    am I able to sniff now, but the performance improved as well since
    the Cisco card does the WEP encryption on the card (unlike the
    Linksys where the driver (software) encrypts).
    
    On a side note, wireless sniffing is very much different from LAN
    sniffing. When in promiscuous mode you will not be able to send
    packets at the same time since the whole wireless RTS/CTS handshake
    is done differently.
    
    Regards,
    Frank
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP Personal Privacy 6.5.8
    Comment: PGP or S/MIME encrypted email preferred.
    
    iQA/AwUBOutzr5ytSsEygtEFEQJzZgCg8xg6/4uNNFtSEe1/ttWGd8Ac0hkAn1yP
    1EiSIj79ZsamRJ2MxSpdXGhP
    =DbeY
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Sun Apr 29 2001 - 07:24:58 PDT