LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 06-07-2015, 10:34 AM   #1
gonny95
Member
 
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Rep: Reputation: Disabled
Wireshark monitor mode not working


Distro : Arch Linux x86_64

Hi I'm trying to capture packets with Wireshark in monitor mode.

I ran Wireshark with noraml user and selected interface wlp1s0.
When I pushed the start button, the following error occured:
Code:
Unknown message from dumpcap, try to show it as a string: Can't delete monitor interface mon1 (SIOCGIFINDEX: Bad file descriptor).
Please delete manually.
E
I thought that was permission problem, so I ran Wire shark using sudo but still the same error message box.

Any ideas??
 
Old 06-09-2015, 12:04 AM   #2
exvor
Senior Member
 
Registered: Jul 2004
Location: Phoenix, Arizona
Distribution: Gentoo, LFS, Debian,Ubuntu
Posts: 1,537

Rep: Reputation: 87
Its possible that your interface does not support promiscuous mode.
 
Old 06-09-2015, 12:21 AM   #3
gonny95
Member
 
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Original Poster
Rep: Reputation: Disabled
Okay.. do you know how to check which modes does the interfaces support?
 
Old 06-09-2015, 02:23 AM   #4
gonny95
Member
 
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Original Poster
Rep: Reputation: Disabled
My interface do support promiscuous mode
because Wireshark captures packets in promiscuous mode by default.

Also there appears kernel message.
Code:
[Jun 8 14:20] device wlp1s0 entered promiscuous mode
And my interface also seems to support monitor mode.
The problem is I just can't start capturing in monitor mode.

Code:
 iw phy0 info
Wiphy phy0
	max # scan SSIDs: 20
	max scan IEs length: 425 bytes
	Retry short limit: 7
	Retry long limit: 4
	Coverage class: 0 (up to 0m)
	Device supports RSN-IBSS.
	Device supports AP-side u-APSD.
	Supported Ciphers:
		* CCMP (00-0f-ac:4)
		* 00-0f-ac:10
		* TKIP (00-0f-ac:2)
		* GCMP (00-0f-ac:8)
		* 00-0f-ac:9
		* WEP40 (00-0f-ac:1)
		* WEP104 (00-0f-ac:5)
		* CMAC (00-0f-ac:6)
		* 00-0f-ac:13
		* 00-0f-ac:11
		* 00-0f-ac:12
		* WPI-SMS4 (00-14-72:1)
	Available Antennas: TX 0 RX 0
	Supported interface modes:
		 * IBSS
		 * managed
		 * AP
		 * AP/VLAN
		 * monitor
		 * P2P-client
		 * P2P-GO
		 * P2P-device

Last edited by gonny95; 06-09-2015 at 02:24 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ipw3945 - mode monitor not working slack_baby Linux - Wireless Networking 5 07-13-2007 10:59 AM
ZD1211B in monitor mode 3.5h only captures Beacon and Probes with Wireshark 99.5 HLP Lopes_sma Linux - Networking 1 07-07-2007 01:40 PM
How to configure a ZD1211B wireless stick to monitor mode on Wireshark using Fedora 7 Lopes_sma Linux - Software 8 07-03-2007 09:59 AM
monitor not working in graphics mode LinuxVirgIan Linux - Newbie 11 07-02-2007 05:07 AM
Help with KNOPPIX 5.1.1/wireshark/monitor mode? liko Linux - Software 1 03-12-2007 07:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 07:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration