LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-24-2009, 04:09 AM   #1
Skuro
LQ Newbie
 
Registered: Jun 2008
Posts: 4

Rep: Reputation: 0
Arrow [Solved] Wireshark does not capture trafic even in Promisc mode (AR2425 > AR5007EG)


[Solved] : It was a simple problem... It was in promiscuous mode, the problem was that i enable WPA in my router. And i didn't know i had to add the Key to Wireshark. ( But a doubt now is... How to add a wpa key in a libpcap c code? )

Hi guys,

Short History: Im not in a switched network. Im in my wireless network, and there is traffic. And i could sniff it before, but after changing driver even though i downgrade back to the one i was using i can't get it to work anymore. I can put my card in Promiscuous mode with no problem, but it isn't capturing any traffic besides the one destined to me. What to do? (my card is an Atheros AR5007EG > AR2425 )

Long History:
Im a Network Security Enthusiast, and those days i was playing with my recently Ubuntu 9.04/Jaunty system, installed some random madwifi driver and was sniffing my own wireless network traffic for fun.

Then i decide to test some mac changes. And it was bugged, after a mac change it wouldn't connect back. So i researched, it was a drive issue, updated to the last bleeding edge driver (im using Athk5) and then mac change worked with no problem.

BUT... I couldn't sniff my wireless network traffic anymore, even tough my card is set to Promiscuous mode (i can only capture traffic that was indeed for me...)

I then Unloaded all the wireless modules, uninstalled all wireless drivers. And tried to go back to the first driver i was using, but it didn't work. Tried Stable, Bleeding edge drivers of both Madwifi, and their new project Athk5. Didn't work.

So i decided to use the bleeding edge one (the latest Athk5). But how can i make Promiscuous mode work?

Here's the config it shows in ifconfig:
Quote:
wlan0 Link encap:Ethernet HWaddr 88:a7:38:52:5a:48
inet addr:192.168.1.101 Bcast:255.255.255.255 Mask:255.255.255.0
inet6 addr: fe80::8aa7:38ff:fe52:5a48/64 Scope:Link
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:9657 errors:0 dropped:0 overruns:0 frame:0
TX packets:9218 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:6864547 (6.8 MB) TX bytes:1873515 (1.8 MB)
Skuro, thanks in advance.

Last edited by Skuro; 06-25-2009 at 08:17 PM. Reason: [Solved]
 
Old 04-29-2010, 03:55 PM   #2
breaker1999
LQ Newbie
 
Registered: Apr 2010
Posts: 1

Rep: Reputation: 0
How did you solve this problem? Can you explain please? I have a similar problem.
Thanks...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
why can't display string when wireshark capture package? aleon Linux - Newbie 3 03-26-2009 04:14 AM
How to get a packet capture using WireShark RN16 Linux - General 2 02-08-2009 12:21 PM
promisc mode nawuza Linux - Networking 1 09-24-2008 10:49 PM
promisc mode sulekha Linux - Networking 1 08-23-2008 05:56 AM
How to capture packets using wireshark exl75 Linux - General 24 07-21-2007 02:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration