Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Networking
Home Forums Register Search Today's Posts Mark Forums Read

wireshark not capturing

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 16-May-2008, 07:24 PM
Paul_o Paul_o is offline
Registered Member
Posts: 79
Points: 0 Paul_o has no points
Power: 4
None
Join Date: 18 May 2006
Location: Leicester
Age: 42
Certifications: C&G Advanced diploma in network support
wireshark not capturing

been trying to get wireshark running on my laptop but having trouble getting it to capture on my wireless card. its a cisco aironet cb21ag-e-k9 card. it shows up ok in the interfaces but when you select it it does not capture packets. i have managed to get it working once so i know it does work but since then have not had any success. i have re-installed winPcap and wireshark the card does work ok so the driver are working, not sure what to try next?

 
Reply With Quote
  #2  
Old 16-May-2008, 08:04 PM
onoski's Avatar
onoski onoski is online now
Lifetime Member
Posts: 1,542
Points: 456 onoski has over 250 pointsonoski has over 250 pointsonoski has over 250 pointsonoski has over 250 pointsonoski has over 250 points
Power: 22
None
Join Date: 08 Mar 2007
Location: London. UK
Certifications: MCP, HNC Business IT
WIP: MCSE 2003
Is there a chance you've a desktop PC you can try it on to make sure its not the laptop? You might also want to check ip filtering is not turned on too.

 
Reply With Quote
  #3  
Old 16-May-2008, 08:37 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,656
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
I'm not too sure that wireshark will capture packets from a wireless card, and especially on Windows. I've never been able to get it to do that. There are so many differences between 802.11 and Ethernet that it's almost impossible to do.

Get something like kismet or netstumbler. They are designed specifically for wireless purposes.



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #4  
Old 16-May-2008, 11:36 PM
zebulebu's Avatar
zebulebu zebulebu is online now
Lifetime Member
Posts: 1,736
Points: 4119 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 62
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 34
Certifications: A few
WIP: NCDA, VCP
The problem with capturing wirelessly in Windows lies in the fact that the drivers used by most WLAN adapters in Windows don't support monitor mode, or don't deal properly with 802.11 headers. If you've got it working in the past, I'd suggest that you disable promiscuous mode and see if that works. Of course, even if it does it won't be much use to you unless you're only interested in capturing traffic between your host and an AP.

I'd be surprised if you have got it to work promiscuously in the past - as far as I'm aware, the vast majority of driver adapters, including all forms of Aironet cards, don't support monitor mode. Like I said, try turning promiscuous mode off and see if that helps.

TBH, you really shouldn't bother fannying about with Windows for wireless sniffing, enumeration or hacking - use BackTrack instead. Its a free live Linux distro that boots off CD so you don't have to do anything to your Windows OS and everything works perfectly with most cards (its what BackTrack was designed for!)


The ruptured capillaries in your nose bely the clarity of your wisdom


My crappy youtube vids
 
Reply With Quote
  #5  
Old 17-May-2008, 08:19 AM
Paul_o Paul_o is offline
Registered Member
Posts: 79
Points: 0 Paul_o has no points
Power: 4
None
Join Date: 18 May 2006
Location: Leicester
Age: 42
Certifications: C&G Advanced diploma in network support
Thanks Zeb, yes it works fine in non promiscuous mode. i had backtrack installed as a dual boot but when i installed a new hdd on the laptop i didn't create a linux partition hence trying to get wireshark on windows working. looks like i'll have to move a partition and re-install backtrack. i have run it from the live cd before but prefer to have a proper install. that's today's job sorted.

 
Reply With Quote
  #6  
Old 17-May-2008, 10:22 AM
r.h.lee r.h.lee is offline
Longterm Member
Posts: 862
Points: 944 r.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 pointsr.h.lee has over 500 points
Power: 22
None
Join Date: 18 Mar 2006
Certifications: MCSE, MCP+I, MCP, CCNA, A+
WIP: CCDA
Quote:
Originally Posted by Paul_o View Post
been trying to get wireshark running on my laptop but having trouble getting it to capture on my wireless card. its a cisco aironet cb21ag-e-k9 card. it shows up ok in the interfaces but when you select it it does not capture packets. i have managed to get it working once so i know it does work but since then have not had any success. i have re-installed winPcap and wireshark the card does work ok so the driver are working, not sure what to try next?
Paul_o,

What kind of wireless network are you connected to? Ad hoc? Infrastructure?


MCSE, MCP+I, MCP, A+, CCNA certified
 
Reply With Quote
  #7  
Old 17-May-2008, 12:14 PM
zebulebu's Avatar
zebulebu zebulebu is online now
Lifetime Member
Posts: 1,736
Points: 4119 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 62
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 34
Certifications: A few
WIP: NCDA, VCP
Quote:
Originally Posted by Paul_o View Post
Thanks Zeb, yes it works fine in non promiscuous mode. i had backtrack installed as a dual boot but when i installed a new hdd on the laptop i didn't create a linux partition hence trying to get wireshark on windows working. looks like i'll have to move a partition and re-install backtrack. i have run it from the live cd before but prefer to have a proper install. that's today's job sorted.
Paul - in case you get stuck, there's an excellent video tutorial here detailing how to set up a good, solid dual boot system with Windows & Backtrack


The ruptured capillaries in your nose bely the clarity of your wisdom


My crappy youtube vids
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Networking


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireshark Tutorial - part 4 zebulebu Networking 12 23-Oct-2007 10:53 AM
Snort and Wireshark Fluid Networking 4 25-Jul-2007 10:49 AM
Wireshark / Ethereal Monitoring simongrahamuk Networking 2 15-Dec-2006 11:27 AM


All times are GMT. The time now is 08:30 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages