Penetration Testing mailing list archives
Re: 802.11B and libpcap
From: Andrew Brown <atatat () atatdot net>
Date: Mon, 17 Sep 2001 14:37:02 -0400
what exactly is the different then between 'monitor' mode and promiscuous mode? I took a look at AirSnort, and it seems to be using raw sockets or something, but for sure not libpcap. Was that decision made just out of convenience? Couldn't AirSnort (or at least its packet acquisition piece) be re-written to use libpcap? Then it should work with other hacked drivers like the Cisco as well.
promiscuous mode passes all network traffic received *and* successfully decrypted (regardless of the destination hardware address on the transmitted packet) up to the operating system. this includes arp, ip, ipx, or anything else that runs over regular ethernet. monitor mode passes all 802.11 traffic up to the operating system *without* trying to decrypt it. i imagine this includes all regular "ethernet" traffic, along with 802.11 management frames, etc. 802.11 cards are usually usable when in promiscuous mode, except for some cards that do not transmit packets when in promiscuous mode. 802.11 cards are almost certainly *not* usable when in monitor mode, unless your kernel is doing the rc4 decryption. -- |-----< "CODE WARRIOR" >-----| codewarrior () daemon org * "ah! i see you have the internet twofsonet () graffiti com (Andrew Brown) that goes *ping*!" andrew () crossbar com * "information is power -- share the wealth." ---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/
Current thread:
- 802.11B and libpcap Ronny Vaningh (Sep 14)
- Re: 802.11B and libpcap Robert van der Meulen (Sep 16)
- Re: 802.11B and libpcap Michael H. Warfield (Sep 16)
- Re: 802.11B and libpcap Bill Pennington (Sep 16)
- Re: 802.11B and libpcap David Hulton (Sep 18)
- <Possible follow-ups>
- RE: 802.11B and libpcap Kelley, John (Sep 16)
- RE: 802.11B and libpcap Frank Knobbe (Sep 17)
- Re: 802.11B and libpcap Robert van der Meulen (Sep 17)
- Re: 802.11B and libpcap Andrew Brown (Sep 18)
- RE: 802.11B and libpcap Anton Rager (Sep 18)
- RE: 802.11B and libpcap Frank Knobbe (Sep 18)
- Re: 802.11B and libpcap Michael H. Warfield (Sep 18)
- RE: 802.11B and libpcap Leif Sawyer (Sep 18)
- 802.11/monitor mode (Was: Re: 802.11B and libpcap) Robert van der Meulen (Sep 18)
- Re: 802.11/monitor mode (Was: Re: 802.11B and libpcap) Michael H. Warfield (Sep 18)
- Re: 802.11/monitor mode (Was: Re: 802.11B and libpcap) Robert van der Meulen (Sep 19)
- 802.11/monitor mode (Was: Re: 802.11B and libpcap) Robert van der Meulen (Sep 18)