Ask Your Question
0

Monitor Mode in MacOS Sonoma

asked 2024-03-20 13:11:09 +0000

chase0920 gravatar image

I am trying to find a way to enable monitor mode on my Mac. Is there any way to achieve this in the settings?

edit retag flag offensive close merge delete

2 Answers

Sort by ยป oldest newest most voted
0

answered 2024-06-27 10:07:02 +0000

lfg1337 gravatar image

I figured out a funny 'hack' or workaround that works on MacOS 15.0 (I believe it is developer beta), so you can have live capture even after turning off the sniffer in wireless diagnostics

  1. CMD + SPACE and type "Wireless Diagnostics" ...
  2. Go to the upper menu bar and click Window
  3. In the Window menu, click on Sniffer
  4. Select any random thing and start sniffing packets
  5. Open Wireshark (I ran it as sudo /Applications/Wireshark.app/Contents/MacOS/Wireshark (not sure if you need this or not)
  6. Set your en0 to monitor
  7. You should start seeing packets

You can then stop the Sniffer and you will still be able to see live capture in Wireshark, note: this will obviously turn off your managed wifi connection.

Rinse and repeat anytime you need to see live capture ...

GLHF

edit flag offensive delete link more

Comments

Fun fact: the program used by the Wireless Diagnostics "Sniffer" is (or, at least, is as of Ventura; I haven't tried it on Sonoma or Sequoia) called "tcpdump". Wireless Diagnostics does some unknown magic and then runs tcpdump on en0 with the -I flag.

That magic allows tcpdump to receive packets when monitor mode is turned on; it appearently allows any program, including dumpcap (which Wireshark runs to do its capturing), to do so. From what you say, at least in Sonoma, that means that any program that opens a Wi-Fi device for capturing while the magic is in place continues to be able to see monitor-mode traffic even after the program that did the magic stops tcpdump. I have some memory that you have to tweak the Wi-Fi adapter to re-associate with your network, so perhaps Wireless Diagnostics doesn't turn off the magic after stopping tcpdump.

Guy Harris gravatar imageGuy Harris ( 2024-06-27 20:34:41 +0000 )edit
0

answered 2024-03-20 13:55:43 +0000

grahamb gravatar image

Maybe the OSX section of the WLAN Capture Setup wiki page will help.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2024-03-20 13:11:09 +0000

Seen: 2,426 times

Last updated: Jun 27