nmap / npcap

Nmap Project's Windows packet capture and transmission library
https://npcap.com
Other
2.97k stars 514 forks source link

Malformed 802.11 packets in Monitor Mode #87

Open BehindTheSciences opened 6 years ago

BehindTheSciences commented 6 years ago

I'm getting all malformed packets when I do

tshark -i 3 -I -w C:\pcaps\capture.pcapng

Same when I run Wireshark and enable the monitor mode in the WiFi Adapter interface.

My system is:

This is how all the captures look: capture

Has anyone tried this successfully?

dmiller-nmap commented 6 years ago

This looks like pretty decent support, but I can't see in your screenshot exactly what is malformed. We are tracking network card/driver support on this page at SecWiki. The "How to help" section has information about checking for various levels of support. Can you give us more information along those lines? Thanks.

BehindTheSciences commented 6 years ago

@dmiller-nmap Thanks for the guidelines. I've checked the driver version and when tried to upgrade it, it says this is the latest version:

device_manager

Also, on Wireshark, I see the monitor mode option: screenshot1

But all packets are malformed and the power is 0dBm. screenshot2 Alse, here is the pcap file.Thanks a lot!

carloseduleal commented 6 years ago

I'm facing the same issue, all the values that I need (data rate, signal, noise, ht & vht capabilities) are 0 as the value. Following the post to get some answers.

dmiller-nmap commented 6 years ago

@carloseduleal Please see the hardware/driver support page on SecWiki.org. If you can provide information about your network card and driver, we can update our support page. Not all manufacturers include this functionality.

dmiller-nmap commented 6 years ago

@BehindTheSciences Is this the adapter you are using: https://wikidevi.com/wiki/ALFA_Network_AWUS036NH ? I want to be sure we record everything correctly. You will find download links for drivers on that page, too. They may work better, or they may be worse. Either way, we would greatly appreciate if you can help us investigate.