Thank you for the write up, will have to try it out as soon as christmas is over and I get some free time on my hands again. Never had any luck playing with ettercap on an at interface, neither using it to bridge the connection or simply sniff the traffic, but might just have overlooked the -p setting to disable promiscuous mode.
Apart from that I have not noticed any restrictions using airbase-ng under VMware, and do not recall seeing any malformed packets using wireshark, but guess I will have to look into this some more.





I did nevertheless need to modify the script to use MTU 1500 on at0, without which the previously described issue would occur. I also still seem to have problems connecting to the rogue AP when using the -P -C switches in airbase-ng. I also noticed the malformed packets in Wireshark when monitoring the wlan0 interface, this is however easily overcome by simply using the at0 interface instead, which is why I didn't notice it previously. I also seemed to be able to run mdk3 alongside airbase-ng using the same interface. I say seemed at this point as I have only confirmed that they both are able to run alongside each other without problems, but have not further investigating how well mdk3 works in this manner.
