NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 03-04-2002   #1 (permalink)
 
Posts: n/a
AirSnort difficulties (Mandrake 8.1 w/ Prism2 card)

Hi all,

Thanks for taking the time to have a peek at my post!

I finally got my linux setup working with a Prism2 card (have both SMC card and Lucent Orinoco Gold) .. now that I have the Prism card working under linux .. I tried to use AirSnort .. here's the problem:

when I do a "capture" session (capture -c <filename>) it _does_ show a packet count .. but _doesnt_ seem to save to the "capture file" ... can anyone help me out here?
  Reply With Quote
Old 03-05-2002   #2 (permalink)
 
Posts: n/a
Does it work with prismdump? Are you throwing it into promisc before you start airsnort?

  Reply With Quote
Old 03-05-2002   #3 (permalink)
 
Posts: n/a
Also.. It'll only save "Interesting" packets.. Check with prismstumbler. You're probably doing just fine, you just havn't gotten anything usefull yet..
  Reply With Quote
Old 03-05-2002   #4 (permalink)
 
Posts: n/a
Prism II and wardriving/monitor mode

Forget Airsnort. That is primarily a tool for cracking weak WEP encryption. You will likely RARELY find a weak-encrypted network these days. You either find MANY with no obvious encryption (they may be using some other means like ssh, ssl, VPN, etc, which makes getting in REAL unlikely) or you can just connect because there is absolutely no control at all.


I use kismet. Check it out. Produces a VERY nice konsole information output. It also logs everything for analysis - you can open the dump file in ethereal and peruse at your leisure. With the kismet up and running, you get a list of network names, whether or not WEP is used, if the system is an Access Point or an adhoc setup, whether or not dhcp is used, what the IP address range is, whether or not it is weak encryption (40 bit), what chanel it is on, what sort of activity is on the network (count of data packets being sent vs simply LLC broadcast packets). It also logs cisco packets and provides a log of weak packets alone (never seen it pick any up because most people have gotten off 40 bit) and a simple readable list of networks: their names/ssid, channel, mac address of the AP or adhoc station. Real nifty app. I use it with a netgear MA401 (sucky card) and my Zoomair connected to a parabolic or other homemade directional antenna (nice card).

Kismet is at:
http://www.kismetwireless.net

You can also look for prismsnort, which combines the functions of prismdump and airsnort. The console screen is identical to that of airsnort (not much info compared to kismet) and it produces an ethereal-friendly dump as well - and can crack weak WEP networks too.
  Reply With Quote
Old 03-05-2002   #5 (permalink)
 
Posts: n/a
Thanks to all who replied!

I did not see the "interesting packet" counter increment at all - thus, the dump file was empty.

I have recently been muddling with Kismet and rather like it (in combination with Ethereal)

I have an interesting question now .. without any packets being sent (aside from beacon packets) .. can you determine what IP address the device is using if you know the MAC address? .. this probably seems like an ultra-newb question - but none the less is valid. The reason I ask is because by sending a modified TCP packet, one should be able to solicit a response, no?
  Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 12:20 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.