![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
What are the options for packet capture using an iPaq 5550?
I've tried using vxSniffer but it reports that the iPaq's internal WiFi does not support promiscuous mode and, although no errors are reported, nothing is captured with an Avaya with Orinoco drivers. Both MS and WiFiFoFum can see my AP using either the internal or Avaya NIC. Airscanner is not an option as the 5550 runs WM2003. I've heard mention of the next version of Airodump running on PPC but that's still some way off. Options? Thanks.
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
#3 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
http://www.agere.com/mobility/docs/w...r_sr02-2.3.zip Also, how do I go about telling the iPaq to use a different driver for a card that already has a driver installed? Thanks
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#4 (permalink) | |
|
Registered Member
Join Date: May 2004
Posts: 59
|
Quote:
It is possible to choose which driver you want to use by modifying a registry entry. Here's how it goes: Go to HKLM\Comm\PCI\<the card you are using>. Remember the exact name of <the card you are using>. Then go to HKLM\Drivers\PCMCIA\<the card you are using>. You will see a String Value called "Miniport". If you want to use the Agere drivers, modify there value to "WLAGS46". For Orinoco, "WLLUC46"(in my case this is my orinoco driver). I'm not sure if this is old news, but I've found out that using the Orinoco drivers allows spoofing of mac address while the Agere ones isn't possible. |
|
|
|
|
|
|
#5 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
With the Orinoco drivers installed VxSniffer sees: "ORiNOCO PC Card (5 Volt)" With the Agere driver VxSniffer sees: "Agere Wireless Network Driver (H1)" and "Agere Wireless Network Driver (H2)" If I select "Agere Wireless Network Driver (H1)" then it is just like with the Orinoco driver. MS and WiFiFoFum show my AP and VxSniffer gives no errors but captures no packets. If I select "Agere Wireless Network Driver (H2)" then VxSniffer gives the error: "Cannot open adapter Agere Wireless Network Driver (H2)"
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#6 (permalink) | |
|
Registered Member
Join Date: May 2004
Posts: 59
|
Quote:
|
|
|
|
|
|
|
#7 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
I am an idiot. Feel free to call me such for that is what I am. Yes, there is network traffic and has been all along. The Agere driver is working perfectly and I suspect the Orinoco was too. It looks like the problem is that I did not understand the difference between promiscuous mode and rfmon mode. The card was not actually associated with the AP at the time of the scan. Now, how do I get this thing to capture all packets broadcast on a given channel a la Airodump or is that beyond the abilities of VxSniffer? Thanks.
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#8 (permalink) | |
|
Registered Member
Join Date: May 2004
Posts: 59
|
Quote:
![]() |
|
|
|
|
|
|
#9 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
So, do you know of any tools for PPC that do this or is it back to waiting for Airodump for PPC?
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#10 (permalink) | |
|
Registered Member
Join Date: May 2004
Posts: 59
|
Quote:
|
|
|
|
|
|
|
#11 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
I just tried out the 2.1 package. Very nice indeed. wzcook is a nice addition to the windows versions. I am especially impressed with 802ether that can convert airodump's .pcap files to a format readable by GMT. My AP doesn't support WPA so I can't see how that is handled yet. Probably going to wait for AES before upgrading. I wonder what devine has in the works for AES. Still hoping for airodump for PPC.
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#12 (permalink) |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Damn it!
I thought I was on to something for a while but, allas, no. Anyone had success with CENiffer or CEMyNetwork? I've downloaded the demos but can't get anywhere as they need a ticket to run and, for whatever reason, I can't get a ticket even with an internet connection.
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
#13 (permalink) | |
|
Registered Member
Join Date: May 2004
Posts: 59
|
Quote:
Yup, there seems to be a problem with CEniffer 3.2. Neither could I get a ticket. I've tried the demo version of 3.1 before too, it runs but doesnt seem to work on wm2003. |
|
|
|
|
|
|
#14 (permalink) | |
|
I'm a doctor, not a...
Join Date: Jul 2004
Location: U.K.
Posts: 94
|
Quote:
Airscanner - WM2002 only. vxSniffer - No RFMon mode. CENiffer - Pile of crap. All together now: "We want Airodump, we want Airodump..."
__________________
Is that a Tricorder in your pocket or are you just pleased to see me? |
|
|
|
|
|
|
#15 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
Well I don't have a PPC compiler, let alone a PPC, so it will take time. However I'm in touch with a pda developper from brazil who's helping me on this matter. |
|
|
|
|