Penetration Testing mailing list archives

RE: 802.11B and libpcap


From: Frank Knobbe <FKnobbe () KnobbeITS com>
Date: Mon, 17 Sep 2001 09:28:07 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

-----Original Message-----
From: Robert van der Meulen [mailto:rvdm () cistron nl]
Sent: Sunday, September 16, 2001 8:33 AM

Quoting Ronny Vaningh (ronny.vaningh () be uu net):
Also, what is so special in the PRISMII cards that airsnort 
only works
with them, and can you recommend any card in particular.

The only thing i could make out from the driver sources of 
the prismII and
the hermes-based cards, is that the 'MONITOR' mode currently 
only works in
the prismII driver; you need 'MONITOR' mode for stuff like this.


Robert,

what exactly is the different then between 'monitor' mode and
promiscuous mode? I took a look at AirSnort, and it seems to be using
raw sockets or something, but for sure not libpcap. Was that decision
made just out of convenience? Couldn't AirSnort (or at least its
packet acquisition piece) be re-written to use libpcap? Then it
should work with other hacked drivers like the Cisco as well.

Regards,
Frank

-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.8
Comment: PGP or S/MIME (X.509) encrypted email preferred.

iQA/AwUBO6YId5ytSsEygtEFEQJx8wCgnSWHaZ4sL0e66XsyaqZDoq8VgvgAoLzJ
VgjqfvEUSm4ha36Cfy7IbvJb
=j0h0
-----END PGP SIGNATURE-----

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: