Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Thread: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

  1. #1
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    6

    Default Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    Hi,

    I'm trying to capture the packets on my wifi router at home and for some reason i can only see incoming packets for my remote PC, no outgoing packets captured in wireshark(same thing with tcpdump).

    My wireless card is Alfa AWUS036H USB adapter with mac80211 driver.

    i found this post with the same problem.

    My built in Broadcom BCM4312 works in promiscuous mode without any problem

    Any help will e much appreciated.

  2. #2
    Super Moderator Archangel-Amael's Avatar
    Join Date
    Jan 2010
    Location
    Somewhere
    Posts
    8,012

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    I am going to guess either it's a problem with your card. Or your commands.
    Post the tcpdump command you used and the output. Pastebin the link here. It may help.
    To be successful here you should read all of the following.
    ForumRules
    ForumFAQ
    If you are new to Back|Track
    Back|Track Wiki
    Failure to do so will probably get your threads deleted or worse.

  3. #3
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    6

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    I put my card in monitor mode: airmon-ng start wlan1

    And then run tcpdump,

    here is the command and output http://pastebin.com/MajPafMp

    I'm using open network.

  4. #4
    Junior Member laptopz's Avatar
    Join Date
    Dec 2010
    Posts
    55

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    try the same with mon0
    If anything can go wrong, it will....

  5. #5
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    6

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    i tried on mon0 also - http://pastebin.com/pPDRc0LH

    i think on mon0 i don't get even incoming traffic.

    In my first post i tested it on Ubuntu where my built in Broadcom worked very well with wireshark in promiscuous mode

    I have installed BT RC2 and now Broadcom has the same behavior only incoming packets more than that it is very not stable i get disconnection all the time

  6. #6
    Junior Member laptopz's Avatar
    Join Date
    Dec 2010
    Posts
    55

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    I believe i misunderstood what you are trying to do...
    About not seeing outgoung packets : Correct me if i`m wrong, but when in monitor mode the wireless card stops transmitting data and only "sniffs" the current channel...

    Here is some WIreshark-FU
    Last edited by laptopz; 01-20-2011 at 10:21 PM.
    If anything can go wrong, it will....

  7. #7
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    6

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    What i'm trying to do is to connect my laptop to my own wifi and sniff the network in promiscuous mode on that AP in order to get traffic from different devices connected to it.

    The best results i achieved till now is to get incoming/outgoing traffic from my remote pc but with a lot of packet loss/missing packets. And this is when i disconnect my card from the AP, killing all processes that using the card and running it in monitor mode.

    My question is can i sniff the network in promiscuous mode while i'm connected to the same AP.

  8. #8
    Very good friend of the forum TAPE's Avatar
    Join Date
    Jan 2010
    Location
    Europe
    Posts
    599

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    Now I may be completely wrong here, but I think you are probably dealing with a similar situation
    I was on a while ago.
    I was basically just wanting to connect to my own network and see what I could get off the
    network activity from the other PCs / Laptops connected to my network.
    (I do stress this is my own network)

    When it comes down to switches you may have to look into a MiTM in order to get the info you
    may be looking for.
    So do a bit of reading up on ARP spoofing and Ettercap and see if that is going to lead you in the
    right direction.


    I did a little write up on my stupidity on not finding that out sooner and perhaps you are looking for something similar ;

    http://adaywithtape.blogspot.com/2010/03/network-captures-revisited.html

  9. #9
    Just burned his ISO
    Join Date
    Jan 2011
    Posts
    6

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    Hi laptopz,

    Thanks for the article. It's very useful.

    Actually i'm using the same method of entering my card to monitor mode on specific channel and trying to capture the packets from my second PC.

    Unfortunately there are a lot of packet loss(around 50%).

    I wonder maybe i miss something or the packet loss in monitor mode is something known. I do not expect for 100% of packets, but 50% is to much and you can't reassemble HTTP session for example.

    I really need advice here.

  10. #10
    Junior Member laptopz's Avatar
    Join Date
    Dec 2010
    Posts
    55

    Default Re: Wireless sniffing with wireshark in promiscuous mode and AWUS036H problem

    Your answers are all in there. Read chapters "Range in wireless networks", "Interference and Collisions" and the following "Recommendations.."
    If anything can go wrong, it will....

Page 1 of 2 12 LastLast

Similar Threads

  1. Wireless sniffing with wireshark and AWUS036H problem
    By ttriple8 in forum Beginners Forum
    Replies: 3
    Last Post: 08-05-2010, 11:18 PM
  2. Alfa Awus036h - and Wireshark promiscuous problem
    By MoonDoggie in forum Beginners Forum
    Replies: 3
    Last Post: 06-04-2010, 10:32 AM
  3. 4965agn and promiscuous mode in wireshark
    By walkamongus in forum Beginners Forum
    Replies: 0
    Last Post: 05-31-2010, 10:37 PM
  4. Promiscuous mode problem with HWUG1
    By btnoob in forum OLD Newbie Area
    Replies: 5
    Last Post: 04-21-2009, 10:34 PM
  5. Replies: 3
    Last Post: 03-21-2009, 04:13 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •