Ask Your Question

esotechnica's profile - activity

2020-05-07 14:55:31 +0000 received badge  Famous Question (source)
2020-05-07 14:55:31 +0000 received badge  Notable Question (source)
2020-05-07 14:55:31 +0000 received badge  Popular Question (source)
2020-02-01 13:34:27 +0000 received badge  Notable Question (source)
2020-02-01 13:34:27 +0000 received badge  Popular Question (source)
2019-08-02 12:56:51 +0000 marked best answer Persistent problems with Wireshark capturing WLAN high datarate frames

I have never had any luck capturing anything useful with Wireshark in monitor mode. It seems to be a problem with capturing high speed WLAN frames. In a previous post I detail the problems I had with my WLAN adapter not being able to capture all packets unless I downgrade the AP from 802.11n to 802.11b/g.

Assuming that it was the WLAN adapter that was the problem, I have recently purchased an Alfa AWUS036ACM AC1200 WLAN adapter. This is the card recommended by aircrack-ng as the best card for wireless packet sniffing. However, I still have the exact SAME problem as before, I can only see low-rate frames over the air.

Please, can someone tell me is it actually possible AT ALL to capture the high rate frames of 802.11n and 802.11ac, and how I can troubleshoot this issue?

NOTE: I have no trouble setting this device into monitor mode. It sees frames from other stations, just not the ones I need. Decryption works fine too.

2019-08-02 12:56:36 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

I've managed to workout my issue with the iw command, using the iw and ip commands together require a particular order i

2019-07-28 10:29:55 +0000 received badge  Commentator
2019-07-28 10:29:55 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

OK, disregard the last question, I found the MCS sets. It appears that my phone (Samsung s9+) supports MCS 0-9 for up t

2019-07-28 01:58:27 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

My 802.11ac AP is configured to channel 44 with a 20MHz channel width with SGI disabled (I override the channel width to

2019-07-28 01:16:40 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

My 802.11ac AP is configured to channel 44 with a 20MHz channel width with SGI disabled (I override the channel width to

2019-07-28 00:27:17 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

I've not had any luck setting the adapter channel using iw command. I always get "command failed: Device or resource bu

2019-07-25 04:12:59 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

I suppose the short answer to "what do I want to do" is to simply collect every frame broadcast on a particular channel

2019-07-25 04:03:54 +0000 commented answer Persistent problems with Wireshark capturing WLAN high datarate frames

Sorry for the confusion, I have amended the title, I meant I don't get any high-rate frames at all from the air...

2019-07-24 21:14:41 +0000 edited question Persistent problems with Wireshark capturing WLAN high datarate frames

Persistent problems with Wireshark capturing high WLAN dataframe rates I have never had any luck capturing anything usef

2019-07-24 21:14:29 +0000 edited question Persistent problems with Wireshark capturing WLAN high datarate frames

Persistent problems with Wireshark capturing high rate frames I have never had any luck capturing anything useful with W

2019-07-24 10:58:16 +0000 edited question Persistent problems with Wireshark capturing WLAN high datarate frames

Persistent problems with Wireshark capturing high rate frames I have never had any luck capturing anything useful with W

2019-07-24 10:55:53 +0000 received badge  Editor (source)
2019-07-24 10:55:53 +0000 edited question Persistent problems with Wireshark capturing WLAN high datarate frames

Persistent problems with Wireshark capturing high rate frames I have never had any luck capturing anything useful with W

2019-07-24 10:54:35 +0000 asked a question Persistent problems with Wireshark capturing WLAN high datarate frames

Persistent problems with Wireshark capturing high rate frames I have never had any luck capturing anything useful with W

2019-07-08 05:50:48 +0000 commented answer Cannot capture unicast WLAN packets from any station

It's certainly interesting that in monitor mode, it can only capture b/g traffic and yet can capture 802.11n in managed

2019-07-07 11:19:32 +0000 marked best answer Cannot capture unicast WLAN packets from any station

I am trying to sniff regular data frames over WLAN with Wireshark, but am unable to capture ANY unicast frames at all.

I have created a monitor mode virtual interface (mon0) of my WLAN interface using the iw command. I get broadcast/multicast packets, as well as a ton of management/control frames, but no unicast packets, not even from the capture PC that I am running Wireshark from, let alone from any other WLAN devices on the network.

I am running Arch Linux (Linux 5.0.10) using a TP-Link WLAN adapter with a Qualcomm Atheros AR9287 chipset. I would be grateful if anyone could suggest a reason why this is not working properly?

2019-07-07 11:19:32 +0000 received badge  Scholar (source)
2019-07-07 11:19:20 +0000 commented answer Cannot capture unicast WLAN packets from any station

Success! By disabling SGI and setting to b/g mixed mode, I can now see everything. Thanks so much for your help.

2019-07-07 10:47:16 +0000 commented answer Cannot capture unicast WLAN packets from any station

Hi Bob, by unicast frames I mean looking for any 'useful' data frames carrying TCP/IP traffic that are not broadcast/mul

2019-07-07 00:17:40 +0000 commented question Cannot capture unicast WLAN packets from any station

Using airmon-ng I have now created a new monitor mode interface (rather than using iw) called wlp4s0mon. This interface

2019-07-06 23:44:27 +0000 commented question Cannot capture unicast WLAN packets from any station

Hi Bob, if I try capturing from mon0 when the actual WLAN interface (wlp4s0) is down, I get no packets at all. I'm gues

2019-07-06 04:25:00 +0000 asked a question Cannot capture unicast WLAN packets from any station

Cannot capture unicast WLAN packets from any station I am trying to sniff regular data frames over WLAN with Wireshark,