Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow SPAN over wifi
EH-Net
May 20, 2013, 11:57:07 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: SPAN over wifi  (Read 3681 times)
0 Members and 1 Guest are viewing this topic.
kerpap
Newbie
*
Offline Offline

Posts: 8



View Profile
« on: June 15, 2012, 04:56:46 AM »

is there a way to sniff all network traffic on an AP similar to SPAN on a switch?
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1631



View Profile
« Reply #1 on: June 15, 2012, 07:53:22 AM »

Removed my last reply (sorry,) as I'd misread your post, the first time.

That said, if you can talk to wired clients from your wireless, and vice versa, then a hint might be to start Googling "ARP poisoning"   Wink

That's how many people bypass the need for a 'monitor' port on a switched network, etc, to successfully sniff.
« Last Edit: June 15, 2012, 08:08:31 AM by hayabusa » Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
hayabusa
Hero Member
*****
Offline Offline

Posts: 1631



View Profile
« Reply #2 on: June 15, 2012, 08:12:33 AM »

Here's a couple of good reads for you:

http://www.giac.org/paper/gcih/280/wireless-vulnerability-arp-poisoning/102940

http://scholarworks.sjsu.edu/cgi/viewcontent.cgi?article=1130&context=etd_projects
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
hell_razor
Jr. Member
**
Offline Offline

Posts: 90


View Profile
« Reply #3 on: June 15, 2012, 09:17:17 AM »

802.11 is a broadcast medium.  You can capture all packets, up to the bandwidth of your capture device, freely.  The potential issue is being able to decrypt all of the packets, which should also not be a problem if you have the appropriate keys to the data (PSK hopefully).
Logged

A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
hayabusa
Hero Member
*****
Offline Offline

Posts: 1631



View Profile
« Reply #4 on: June 15, 2012, 01:26:13 PM »

@hell_razor - that's the response I started to lead with, but I think he's looking to sniff the wired ports and traffic, too.  IE - not just broadcast traffic and such on the wireless, but BOTH wireless and wired clients, such that directed, wired ip traffic (host ip to host ip on wired side) are also seen.

Then again, maybe I DOUBLE mis-interpreted, and you're correct in what he wanted, in which case... DOH!  Tongue
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
hell_razor
Jr. Member
**
Offline Offline

Posts: 90


View Profile
« Reply #5 on: June 15, 2012, 05:03:49 PM »

I probably read AP a little too literally, was thinking a simple AP rather than a router with a hub bridged on it...will blame it on being Friday...
Logged

A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
hayabusa
Hero Member
*****
Offline Offline

Posts: 1631



View Profile
« Reply #6 on: June 15, 2012, 07:35:46 PM »

Either way, hopefully we gave him what he wanted.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
WCNA
Full Member
***
Offline Offline

Posts: 187



View Profile
« Reply #7 on: June 16, 2012, 10:15:16 AM »

Check out airmon-ng. Then run wireshark on mon0.
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
kerpap
Newbie
*
Offline Offline

Posts: 8



View Profile
« Reply #8 on: June 19, 2012, 07:52:43 PM »

thanks for all the feedback.

it is an abstract question. I set up a span port on my switch to monitor traffic. the config on my switch will send all traffic since the AP is connected to a switch.

this is all really just for fun anyway.

it got me wondering if there was a way to send the same thing over the air to my laptop. I realize that in an actual production environment that is really stupid. this is purely just for fun at home with my lab

i'll keep playing around. another thing I thought was set an AP up on the SPAN port of the switch although I dont really see how that will work. I might try configuring the AP as a repeater so perhaps the traffic will get broadcast.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.