wireless protocol analyzer/packet sniffer

wahoyaho

Gawd
Joined
Jan 20, 2005
Messages
514
i'm on windows, so i'm not sure if ethereal will work.

will it work? if not what else should i try.
 
Ethereal will work. It wont pick up management frames, or beacons, or anything like that...but it will pick up TCP/UDP/ICMP/etc. It will only work for the access point you're connected to though. It wont pick up everything from every AP in the area.

You could try compiling Kismet, I've heard of people getting it to work on Windows.

AiroPeek is another one, but its not free.
 
net stumbler does what you want it to do.

EDIT: Just looked at it and im not sure about the protocol analyzer (not fam. with it) but you can see who is in the area, and see the signal strength and mac addy, and some other goodies. adn you can see if anyone is on yours.
 
Netstumbler is not a packet sniffer or protocol analyzer.

Netstumbler just shows you visible networks (ie SSID not hidden), MAC address, assumed vendor, channel, signal strength, and some other things. It does all of those very well...but again, it doesnt capture packets, and it wont show you hidden networks.

[EDIT] It's also possible to detect the use of NetStumbler...
 
Boscoh said:
Netstumbler is not a packet sniffer or protocol analyzer.

Netstumbler just shows you visible networks (ie SSID not hidden), MAC address, assumed vendor, channel, signal strength, and some other things. It does all of those very well...but again, it doesnt capture packets, and it wont show you hidden networks.

[EDIT] It's also possible to detect the use of NetStumbler...

The only way you will be able to sniff with windows is if you are on the same hub as the ap. as windows doesn't allow you to passivly sniff with wireless (why netstumbler can get detected, it's active)
 
TekieB said:
The only way you will be able to sniff with windows is if you are on the same hub as the ap. as windows doesn't allow you to passivly sniff with wireless (why netstumbler can get detected, it's active)
There are ways to get Kismet to work with Windows, but as far as I know no one has made a solid port to Windows in large circulation that will allow you to use rfmon drivers. There is a port that uses cygwin but it only allows you to use Kismet Drones, not the wireless card on the PC.

Airsnort and Airodump both can put certain windows cards into rfmon mode, which allows you to sniff an ap without associating to it.
 
I recommend WildPackets Airopeek if you have an Aironet based PCMCIA card. It captures all packets on all channels.
 
Back
Top