Sniffer issues

I’m running wireless → sniffer…single chanel that i KNOW has data is flowing across.

When i read the file dump, ALL i get is a bunch of IEEE 802 Association Requests. no data, nothing useful.

and the actual packet sniifer tool is useless for wifi as we know…not for wired however.


Any ideas as to why sniifer is not showing my flowing traffic?

If you go into that mode doesn’t the AP stop? I wasn’t sure if you could packet sniff and use the AP at the same time.

Sam

yes the AP stops.. but the MAC addys i’m seeing are from a differnt address than the AP anyway..

I should be seeing ANy and ALL traffic on the selected channel, correct?

tks

Something is wrong def. wrong with sniffer.. i can see in winbox interface, data packets plus a TON of beacon packets, when i examine the dump with ethereal all i see are a bunch of IEEE proto beacon messages, no data or anything else afterdoing a sniff.. ive tried 2 different builds / OSs of ethereal as well.

any ideas, or can anyone confim good packet dumps from the wireless sniffer tool?

tks

EDIT: BTW, wireless sniffer used to work fine for me as of six or so months ago and i gues ~ 2.9.20 I dont remeber specifics, just using it a few times successfully to verify that some data was encrypted. (i scanned then downloaded the dump from MT router, and opend with ethereal and saw the sniffed cleartext data).

Anyone?

MT can you confirm that wireless sniifer is working right, that is its sniffing as a card in promiscuous mode.

tks

Did I hear somewhere that only specific wireless chipsets supported that, maybe your using a card that doesnt have it ?

Sam

maybe, but i know i was using a 8602 before and ive tired it ona 3 different cards..

so i dont think thats an issue…are you able to sniff?

tks

If you still have probs on this issue, get Wireshark. It’s Ethereal, but it had a name change around May