Share your knowledge at the LQ Wiki.
Go Back > Forums > Linux Forums > Linux - Newbie
User Name
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!


  Search this Thread
Old 06-07-2015, 11:34 AM   #1
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Rep: Reputation: Disabled
Wireshark monitor mode not working

Distro : Arch Linux x86_64

Hi I'm trying to capture packets with Wireshark in monitor mode.

I ran Wireshark with noraml user and selected interface wlp1s0.
When I pushed the start button, the following error occured:
Unknown message from dumpcap, try to show it as a string: Can't delete monitor interface mon1 (SIOCGIFINDEX: Bad file descriptor).
Please delete manually.
I thought that was permission problem, so I ran Wire shark using sudo but still the same error message box.

Any ideas??
Old 06-09-2015, 01:04 AM   #2
Senior Member
Registered: Jul 2004
Location: Phoenix, Arizona
Distribution: Gentoo, LFS, Debian,Ubuntu
Posts: 1,537

Rep: Reputation: 87
Its possible that your interface does not support promiscuous mode.
Old 06-09-2015, 01:21 AM   #3
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Original Poster
Rep: Reputation: Disabled
Okay.. do you know how to check which modes does the interfaces support?
Old 06-09-2015, 03:23 AM   #4
Registered: Feb 2014
Distribution: Slackware,Ubuntu
Posts: 84

Original Poster
Rep: Reputation: Disabled
My interface do support promiscuous mode
because Wireshark captures packets in promiscuous mode by default.

Also there appears kernel message.
[Jun 8 14:20] device wlp1s0 entered promiscuous mode
And my interface also seems to support monitor mode.
The problem is I just can't start capturing in monitor mode.

 iw phy0 info
Wiphy phy0
	max # scan SSIDs: 20
	max scan IEs length: 425 bytes
	Retry short limit: 7
	Retry long limit: 4
	Coverage class: 0 (up to 0m)
	Device supports RSN-IBSS.
	Device supports AP-side u-APSD.
	Supported Ciphers:
		* CCMP (00-0f-ac:4)
		* 00-0f-ac:10
		* TKIP (00-0f-ac:2)
		* GCMP (00-0f-ac:8)
		* 00-0f-ac:9
		* WEP40 (00-0f-ac:1)
		* WEP104 (00-0f-ac:5)
		* CMAC (00-0f-ac:6)
		* 00-0f-ac:13
		* 00-0f-ac:11
		* 00-0f-ac:12
		* WPI-SMS4 (00-14-72:1)
	Available Antennas: TX 0 RX 0
	Supported interface modes:
		 * IBSS
		 * managed
		 * AP
		 * AP/VLAN
		 * monitor
		 * P2P-client
		 * P2P-GO
		 * P2P-device

Last edited by gonny95; 06-09-2015 at 03:24 AM.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
ipw3945 - mode monitor not working slack_baby Linux - Wireless Networking 5 07-13-2007 11:59 AM
ZD1211B in monitor mode 3.5h only captures Beacon and Probes with Wireshark 99.5 HLP Lopes_sma Linux - Networking 1 07-07-2007 02:40 PM
How to configure a ZD1211B wireless stick to monitor mode on Wireshark using Fedora 7 Lopes_sma Linux - Software 8 07-03-2007 10:59 AM
monitor not working in graphics mode LinuxVirgIan Linux - Newbie 11 07-02-2007 06:07 AM
Help with KNOPPIX 5.1.1/wireshark/monitor mode? liko Linux - Software 1 03-12-2007 08:16 AM > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:30 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration