LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-06-2007, 09:38 AM   #1
Lopes_sma
LQ Newbie
 
Registered: Jul 2007
Posts: 9

Rep: Reputation: 0
Exclamation ZD1211B in monitor mode 3.5h only captures Beacon and Probes with Wireshark 99.5 HLP


Guys I have one serious problem capturing packets using a ZD1211B chip based usb dongle on Fedora 7 and Wireshark



I've struggled to change my wireless usb dongle to monitor mode but now I know how to do it.



Here's the code:



/sbin/service NetworkManager stop

/sbin/chkconfig NetworkManager off

/sbin/ifconfig wlan0 down

/sbin/iwconfig wlan0 mode monitor

/sbin/ifconfig wlan0 up

/sbin/iwconfig wlan0 channel 11

/sbin/iwconfig wlan0

wlan0 IEEE 802.11g Mode:Monitor Frequency:2.462 GHz
Retry min limit:7 RTS thrff Fragment thr=2346 B
Encryption keyff
Link Quality:0 Signal level:0 Noise level:0
Rx invalid nwid:0 Rx invalid crypt:0 Rx invalid frag:0
Tx excessive retries:0 Invalid misc:0 Missed beacon:0





Then I open Wireshark hit capture interfaces (with promiscuous mode seleted) and right there my wlan0 starts to count packets.

But when I start capturing I only get Beacons Probes and unresolved.



In my last capture for 3.5 hours I got around 200.000 packets mostly beacons probes and only 2 of them were IPX.

No http or any other protocols were found and I got around 50 endpoints and 10 diferent SSID's!!


Besides my WLAN using Windows and Fedora 7 I've found 4 medium/low signal WLAN beaconing their SSID...


Something has to be wrong!!!!
Can you help me solve this?
 
Old 07-07-2007, 01:40 PM   #2
whistl
Member
 
Registered: May 2005
Location: USA
Distribution: Ubuntu, CentOS
Posts: 37

Rep: Reputation: 15
monitor mode

it sounds like your wifi driver isn't putting the chip into monitor mode properly. You don't mention which distribution or kernel version you are using. You might find something useful at http://zd1211.wiki.sourceforge.net/VendorBasedDriver

good luck!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to configure a ZD1211B wireless stick to monitor mode on Wireshark using Fedora 7 Lopes_sma Linux - Software 8 07-03-2007 09:59 AM
Wireshark in promiscuous mode TotalLinuxNoob Linux - Wireless Networking 5 06-20-2007 02:58 PM
iwconfig mode monitor Error: "Set Mode" (8B06) WOP1337 Linux - Wireless Networking 2 04-03-2007 08:13 AM
Help with KNOPPIX 5.1.1/wireshark/monitor mode? liko Linux - Software 1 03-12-2007 07:16 AM
How Read the Timestamp from Beacon Frame? (c code) parisisal Linux - Wireless Networking 0 06-02-2005 04:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration