Username / email:   Password:
or or
Exit Theater Mode

Login or register to enable this feature.

Or, compose an email to send yourself.

Share this video
  • Share via email

Embed or link to this episode

View by:

Packet Sniffing 101: Promiscuous Mode

Monday, May 30th, 2011 – running time 06:52
We're getting promiscuous, with wireless cards! As part of our foundation series of HakTips Darren covers the fundamentals of wireless packet sniffing with a practical approach in BackTrack Linux using the Aircrack-ng suite.

Let's think about network traffic as a cocktail party. Picture Alice and Bob on the love seat chatting it up while Charlie is deep in conversation with Dave at the bar. Meanwhile, Eve is nearby sipping a Hendrix Martini listening in on everyone's conversations.

You see, in order for Alice to send a message to Bob she has to address it to him by his network interfaces MAC address -- or Media Access Control Address. This address is unique every network interface on the planet. Bob's is going to be different from Charlie's, Dave's or anyone else.

On a hub based network, Alice's message is heard by all. But by default when Charlie or Dave hear a message addressed to a mac address other their own, their network interface will drop the frame completely.

This is where promiscuous mode comes into play. If Eve's network interface is in promiscuous mode she doesn't drop frames not addressed to her. This is great for packet sniffing, say if Eve was a network administrator attempting to debug a faulty network. Likewise, if Eve had malicious intent the same applies to eavesdropping.

Now promiscuous mode assumes a hub based network. Switches thwart this by only sending messages to their intended recipients instead of everyone.

Which brings us to Monitor mode. Monitor mode, or RFMON for Radio Frequency Monitor, is one of six modes that wireless network interfaces can assume. Similar to Promiscuous mode, Monitor mode allows the wireless network interface to "sniff packets" not intended for it.

Unline promiscuous mode however, an interface in monitor mode can sniff packets from access points it isn't even associated with. Again this is great for, say, an administrator troubleshooting a network, or on the darker side for malicious purposes such as eavesdropping and cracking encrypted networks.


What program or command is giving you warm fuzzies? Hit me up -- tips@hak5.org

And be sure to check out our sister show, Hak5 for more great stuff just like this.


Hak5
With more than 20 million members, Netflix is the world's largest subscription service instantly streaming TV episodes and movies over the Internet and sending DVDs by mail. Members can instantly watch thousands of titles on a vast array of devices streaming TV episodes and movies like Microsoft's Xbox 360, Sony's PS3 game console and the Nintendo Wii console. As a Netflix unlimited member you can instantly watch as many movies as you want anytime you want for one low monthly price. There are no late fees or due dates. As a new member and a Hak5 Tip viewer, you can get a FREE Trial membership. Go to netflix.com/Hak5 and sign up NOW. Be sure to use this URL so that they know we sent you!