Comments (4)
I should have listed this in the bugs section - certain wireless cards are prone to this, for example the TPLINK TL-WN722N. Other cards, like the Alfa Awus036h seem to perform better. I spent a lot of time last year trying to implement the Wireshark FCS algorithm from C (in Wireshark) to Python to patch Scapy, but didn't succeed in the end. Read my question on the Scapy mailing list here:
http://comments.gmane.org/gmane.comp.security.scapy.general/4918
And the Wireshark C code for the FCS:
https://gist.github.com/glennzw/6365693
I'm trying to find my Python FCS implementation (that was not quite working) to see if you'd have any insight into fixing it. I think it's on a VM back at home, I'll check and update this thread when I find it.
We'd add this to prefilter.py (https://github.com/sensepost/snoopy-ng/blob/master/plugins/mods80211/prefilter/prefilter.py) You can see the dirty hack I've got in there at the moment.
Also, I've recently discovered Impacket:
https://code.google.com/p/impacket/
It has native support for FCS checking, and potetially better performance than Scapy. Well, I'll re-implement and compare performance.
from snoopy-ng.
Yes, TP-LINK - exactly what I'm using in my tests. Happy to check out the Python FCS implementation if you can resurrect it.
Impacket looks very promising indeed, I haven't seen that before myself.
I've actually got a tshark-based probe and beacon sniffing PoC here in the meantime:
https://github.com/maximcherny/snoopy-ng/blob/headway/plugins/tshark.py
If you are interested in pulling that in that please let me know. This one does not deal with handshake capture or cookie snarfing though.
from snoopy-ng.
That'd be useful to have as a separate plugin perhaps - wifi-maxim
or some-such?
from snoopy-ng.
Going back to this - using scapy_ex it is also possible to determine the presence and the value of the FCS flag, I have got working code here:
https://github.com/maximcherny/snoopy-ng/blob/headway/plugins/mods80211/wifi_clients.py
if p.Flags is not None:
if p.Flags & 64 != 0:
self.droppedCount += 1
fcs = 0
elif p.Flags & 64 == 0:
fcs = 1
However, I've collected almost 3 million probes and the flag only appears in roughly 75% of the data, remaining unknown for the rest. While it can be an improvement, it's not a silver bullet. Happy to organise a pull request.
from snoopy-ng.
Related Issues (20)
- Snoopy-ng's Wifi module stops working after a period of time HOT 2
- Is this project still being developed? Are there any other projects doing similar things to Snoopy-ng? HOT 10
- snoopy_auth won't run HOT 3
- libpcap libary not included in Kali 2.0? HOT 1
- six.moves issue, ubuntu 16.04 HOT 4
- Issue authenticating to wiggle HOT 2
- openWRT
- snoopy-ng Kali 2.X - No module named libmproxy HOT 6
- program doesn't work after install HOT 1
- Change location of dpkt in install.sh
- [WARNING] Trouble parsing Bluetooth output: list index out of range HOT 1
- installation failure error command 'x86_64-linux-gnu-gcc' failed with exit status 1 HOT 1
- plz help i got snoopy to install but server wont start HOT 1
- unable to import range HOT 1
- No module named libmproxy HOT 6
- Please fix this so it installs properly HOT 2
- No module name libmproxy!! HOT 1
- issue with pylibcap on ubuntu pcap.c:853:5: error: format not a string literal and no format arguments HOT 4
- dpkt Package not working HOT 2
- Snoopy-ng Client software not working: [!!] Scapy exception whilst sniffing. Will back off for 5 seconds...
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from snoopy-ng.