hidden ssid - broadcast beacons - Question

Bryan Kadzban bryan at kadzban.is-a-geek.net
Mon Aug 13 17:37:19 EDT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160

Stefan Bauer wrote:
> there are a few other frames with includes the ssid's like:
> 
> BEACONs
> PROBE Requests
> PROBE Responses
> ASSOCIATION Requests
> REASSOCIATION Requests
> 
> my question is now how to read the hidden id out of the other frames?

Wireshark on Linux ought to be able to sniff these frames if the
wireless card is in the right mode (not managed, not AP, but the other
mode that I can't recall the name of right now).

If you're stuck with Windows, I've used Airsnort with a decent success
rate, with Atheros hardware.  You can tell it to save to a libpcap file,
and then open that in Wireshark.

You can't sniff them directly on most Windows cards.  (Though the
Wireshark folks sell a USB device that does allow you to.  It's called
AirPcap, or something like that.)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGwM8OS5vET1Wea5wRA4mpAKCrkLrHDyHAE18cZtjhucDAf9gJsQCgr3av
SB84an9VF/ML+RSTS0NvbcY=
=J2F+
-----END PGP SIGNATURE-----



More information about the HostAP mailing list