Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 3 Apr 2002 21:33:37 +0200
From:      Sameh Ghane <sw@anthologeek.net>
To:        Doug Ambrisko <ambrisko@ambrisko.com>
Cc:        Brooks Davis <brooks@one-eyed-alien.net>, "M. Warner Losh" <imp@village.org>, will@csociety.org, mobile@FreeBSD.ORG
Subject:   Re: bsd airtools for current, kernel patches
Message-ID:  <20020403213337.A60018@anthologeek.net>
In-Reply-To: <200204031707.g33H7sW53697@ambrisko.com>; from ambrisko@ambrisko.com on Wed, Apr 03, 2002 at 09:07:53AM -0800
References:  <20020403084114.B6462@Odin.AC.HMC.Edu> <200204031707.g33H7sW53697@ambrisko.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Le (On) Wed, Apr 03, 2002 at 09:07:53AM -0800, Doug Ambrisko ecrivit (wrote):
> | > 
> | > Why is there no generic API for accessing wireless cards ? Are they all that
> | > much different ?
> | 
> | You can snoop raw frames with the Aironet cards by setting the
> | appropriate monitor mode in ancontrol.  Most of these tools should be
> | fairly straight forward to modify to use libpcap to get frames.

I compiled libcap and tcpdump 7 to have 802.11b frames support, and never
managed to get useful output.

> The only caveat is that the Aironet card won't pass up WEP key information
> so you can't do wep crack or decrypt raw packets with the card doing the
> work.  Only the onboard hardware/firmware can do this.  This seems to be 
> confirmed by the Linux users.  I had to do a slight patch to Ethereal/
> tcpdump to ignore the WEP key part of the packet and then the disectors 
> could follow the data in the packet and follow various streams.  Hmm I 
> wonder if I should lie and fake up WEP part so it really looks more like 
> a real 802.11 frame?  This is useful for seeing what strange clients
> are doing.

May I try your patch ? It could help me get helpful output from tcpdump.

Cheers,

-- 
Sameh

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-mobile" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020403213337.A60018>