LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-20-2012, 02:18 PM   #1
newbie0101
Member
 
Registered: Nov 2011
Posts: 47

Rep: Reputation: Disabled
watch all traffic on wlan0 or ethX


hello, i am trying to watch for example http traffic on my wi-fi network of all connected computers.
i'we been using tcpdump an wireshark but those captured only my own traffic.
however when i run command
Code:
ettercap -i wlan0 -TqM ARP:REMOTE // //
then in second console start command
Code:
urlsnarf -i wlan0
can show me traffic of all computers

my question is how can i achieve the same result with tcpdump or wireshark ?
thanks
 
Old 04-20-2012, 04:30 PM   #2
jefro
Moderator
 
Registered: Mar 2008
Posts: 22,001

Rep: Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629
I get the feeling you have a router or switch just before this computer. A switch is different than a hub. A simple hub would send all data to your computer. A switch prevents useless data from being sent.

In some more advanced devices you can mirror or set some settings to allow all traffic to be sent. Some switches have the ability to monitor traffic to some file also.
 
Old 04-21-2012, 01:33 AM   #3
joker20
Member
 
Registered: Sep 2004
Location: 127.0.0.1
Distribution: Slackware/Ubuntu/CentOS
Posts: 286

Rep: Reputation: 31
to touch on what jefro mentioned its called 'port span' which you can configure on your router or switch to take all traffic the device processes and dump it to a specific port where you connect a client machine and sniff the traffic via tcpdump,wireshark,whatever
if you have a standard soho router this may not be possible unless you use a modded firmware like dd-wrt and even then its questionable if you'll get that function (you normally see this done on commerical networking equipment)

but anyway, im sure theres a way to dump the output of urlsnarf to a file and use wireshark to read it in real time for analyzing...never tried it though
post back if you figure something out!
 
Old 04-21-2012, 04:42 PM   #4
jefro
Moderator
 
Registered: Mar 2008
Posts: 22,001

Rep: Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629Reputation: 3629
Thanks, span was the correct term.

http://en.wikipedia.org/wiki/Port_mirroring
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to send all traffic from wlan0 through eth0? mobax Linux - Networking 5 12-14-2010 05:37 PM
HowTo Run a script on ifup ethX and a different one for ifdown ethX dscholl Red Hat 3 07-07-2009 01:09 PM
best way to watch network traffic uselpa Slackware 13 09-10-2008 03:44 PM
wlan0 traffic dependent on eth1! leeko Linux - Wireless Networking 2 06-19-2008 02:22 AM
how to watch the network traffic ? saavik Linux - Networking 6 11-17-2001 08:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration