Ethereal-users: Re: [Ethereal-users] Using Ethereal Windows version for monitoring IEEE 802.11b
At the moment, there is no known way to do this with Ethereal under Windows.
802.11 cards strip off the 802.11 information and pass along plain Ethernet
frames to the host system. To monitor the management frames, you would
need a driver capable of placing the card in "monitor mode", in which the
card simply dumps the raw frames it receives to the host.
AiroPeek (The Windows 802.11 sniffer by WildPackets) does this by using
their own special drivers. They (obviously) only work with certain
cards. Then there's the $2000.00 price tag to consider.
To use Ethereal to monitor 802.11 frames requires (at this time) a Linux
system running a utility called "Prismdump", to which links can be found on
the Ethereal site. Prismdump will put a Prism-II based 802.11 card into
monitor mode and dump the received frames. This can be piped to a FIFO
file that can be read by Ethereal. This is normally used in conjunction
with the linux-wlan-ng package, which gives you the ability to specify
which of the 11 channels you'd care to monitor. Common Prism-II based
cards (that can be found at, say, CompUSA, Best Buy, etc) include SMC,
Linksys, and D-Link. The downside? It is difficult to find Prism-II based
cards with external antenna jacks, so you are normally limited to the
built-in antenna.
If you are determined to use the Windows version (or don't want to take a
stab at the "Linux method"), you'll need to find/write a driver for your
card to place it into monitor mode. Then, you'll have to share your
results with us. :)
- Joe
At 01:04 PM 11/20/2001, you wrote:
Hi All,
I'm trying to use the windows version of Ethereal for monitoring IEEE
802.11b traffic. I have the Lucent/Orinoco Silver WLAN card installed.
In particullar I'm trying to observe the security(WEP) features of the
WLAN, in order to see if some of the various attacks that have been
published during the course of the past year can be easily reproduced.
I was wondering if anyone has done that kind of work and if so could
someone please give me some hints as to how to go about doing this.
Have any of yopu used the windows version to monitor 802.11b traffic and
management messages?
Regards
Sachin S. Mody
Thomson Multimedia, Corporate Research
2 Independence Way,
Princeton, NJ 08543
Ph# 609-734-9494
Fax# 609-734-9870