wifiphisher / wifiphisher

The Rogue Access Point Framework
https://wifiphisher.org
GNU General Public License v3.0
13.31k stars 2.59k forks source link

Hostapd failed to lunch on 5Ghz networks #783

Closed frankjulien closed 6 years ago

frankjulien commented 7 years ago

Hey guys,

Real newbie here, so please, bear with me.

I'm using the latest version of wifiphisher, a USB Wifi adapter (ALFA AWUS051NH v2) + the internal wifi card of my laptop.

As described in the title, everything works well until I select a 5Ghz network from the selection window. When I do, I get the following output:

[*] Starting Wifiphisher 1.3GIT ( https://wifiphisher.org ) at 2017-10-14 23:56
[+] Selecting wlan1 interface for the deauthentication attack
[+] Selecting wlan0 interface for creating the rogue Access Point    
[+] Changing wlan0 MAC addr (BSSID) to 00:00:00:c1:cb:b5
[+] Changing wlan1 MAC addr to 00:00:00:13:19:88
[*] Cleared leases, started DHCP, set up iptables
[+] Selecting OAuth Login Page template
[*] Starting the fake access point...
[!] hostapd failed to lunch!
[+] Show your support!
[+] Follow us: https://twitter.com/wifiphisher
[+] Like us: https://www.facebook.com/Wifiphisher
[+] Captured credentials:
[!] Closing

Everything works well when selecting 2.4Ghz networks. Any ideas why?

hostapd -v output:

hostapd v2.4
User space daemon for IEEE 802.11 AP management,
IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator
Copyright (c) 2002-2015, Jouni Malinen <j@w1.fi> and contributors

iw dev output:

phy#1
    Interface wlan1
        ifindex 4
        wdev 0x100000001
        addr 00:00:00:7a:57:a8
        type monitor
        channel 9 (2452 MHz), width: 20 MHz (no HT), center1: 2452 MHz
        txpower 20.00 dBm
phy#0
    Interface wlan0
        ifindex 3
        wdev 0x1
        addr 00:00:00:79:9d:64
        type managed
        txpower 20.00 dBm

iw list output:

Wiphy phy1
    max # scan SSIDs: 4
    max scan IEs length: 2257 bytes
    max # sched scan SSIDs: 0
    max # match sets: 0
    max # scan plans: 1
    max scan plan interval: -1
    max scan plan iterations: 0
    Retry short long limit: 2
    Coverage class: 0 (up to 0m)
    Device supports RSN-IBSS.
    Supported Ciphers:
        * WEP40 (00-0f-ac:1)
        * WEP104 (00-0f-ac:5)
        * TKIP (00-0f-ac:2)
        * CCMP-128 (00-0f-ac:4)
        * CCMP-256 (00-0f-ac:10)
        * GCMP-128 (00-0f-ac:8)
        * GCMP-256 (00-0f-ac:9)
    Available Antennas: TX 0 RX 0
    Supported interface modes:
         * IBSS
         * managed
         * AP
         * AP/VLAN
         * monitor
         * mesh point
    Band 1:
        Capabilities: 0x17e
            HT20/HT40
            SM Power Save disabled
            RX Greenfield
            RX HT20 SGI
            RX HT40 SGI
            RX STBC 1-stream
            Max AMSDU length: 3839 bytes
            No DSSS/CCK HT40
        Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
        Minimum RX AMPDU time spacing: 2 usec (0x04)
        HT TX/RX MCS rate indexes supported: 0-7, 32
        Bitrates (non-HT):
            * 1.0 Mbps
            * 2.0 Mbps (short preamble supported)
            * 5.5 Mbps (short preamble supported)
            * 11.0 Mbps (short preamble supported)
            * 6.0 Mbps
            * 9.0 Mbps
            * 12.0 Mbps
            * 18.0 Mbps
            * 24.0 Mbps
            * 36.0 Mbps
            * 48.0 Mbps
            * 54.0 Mbps
        Frequencies:
            * 2412 MHz [1] (20.0 dBm)
            * 2417 MHz [2] (20.0 dBm)
            * 2422 MHz [3] (20.0 dBm)
            * 2427 MHz [4] (20.0 dBm)
            * 2432 MHz [5] (20.0 dBm)
            * 2437 MHz [6] (20.0 dBm)
            * 2442 MHz [7] (20.0 dBm)
            * 2447 MHz [8] (20.0 dBm)
            * 2452 MHz [9] (20.0 dBm)
            * 2457 MHz [10] (20.0 dBm)
            * 2462 MHz [11] (20.0 dBm)
            * 2467 MHz [12] (20.0 dBm) (no IR)
            * 2472 MHz [13] (20.0 dBm) (no IR)
            * 2484 MHz [14] (20.0 dBm) (no IR)
    Band 2:
        Capabilities: 0x17e
            HT20/HT40
            SM Power Save disabled
            RX Greenfield
            RX HT20 SGI
            RX HT40 SGI
            RX STBC 1-stream
            Max AMSDU length: 3839 bytes
            No DSSS/CCK HT40
        Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
        Minimum RX AMPDU time spacing: 2 usec (0x04)
        HT TX/RX MCS rate indexes supported: 0-7, 32
        Bitrates (non-HT):
            * 6.0 Mbps
            * 9.0 Mbps
            * 12.0 Mbps
            * 18.0 Mbps
            * 24.0 Mbps
            * 36.0 Mbps
            * 48.0 Mbps
            * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (20.0 dBm) (no IR)
        * 5190 MHz [38] (20.0 dBm) (no IR)
        * 5200 MHz [40] (20.0 dBm) (no IR)
        * 5220 MHz [44] (20.0 dBm) (no IR)
        * 5230 MHz [46] (20.0 dBm) (no IR)
        * 5240 MHz [48] (20.0 dBm) (no IR)
        * 5260 MHz [52] (20.0 dBm) (no IR, radar detection)
        * 5270 MHz [54] (20.0 dBm) (no IR, radar detection)
        * 5280 MHz [56] (20.0 dBm) (no IR, radar detection)
        * 5300 MHz [60] (20.0 dBm) (no IR, radar detection)
        * 5310 MHz [62] (20.0 dBm) (no IR, radar detection)
        * 5320 MHz [64] (20.0 dBm) (no IR, radar detection)
        * 5500 MHz [100] (20.0 dBm) (no IR, radar detection)
        * 5510 MHz [102] (20.0 dBm) (no IR, radar detection)
        * 5520 MHz [104] (20.0 dBm) (no IR, radar detection)
        * 5540 MHz [108] (20.0 dBm) (no IR, radar detection)
        * 5550 MHz [110] (20.0 dBm) (no IR, radar detection)
        * 5560 MHz [112] (20.0 dBm) (no IR, radar detection)
        * 5580 MHz [116] (20.0 dBm) (no IR, radar detection)
        * 5590 MHz [118] (20.0 dBm) (no IR, radar detection)
        * 5600 MHz [120] (20.0 dBm) (no IR, radar detection)
        * 5620 MHz [124] (20.0 dBm) (no IR, radar detection)
        * 5630 MHz [126] (20.0 dBm) (no IR, radar detection)
        * 5640 MHz [128] (20.0 dBm) (no IR, radar detection)
        * 5660 MHz [132] (20.0 dBm) (no IR, radar detection)
        * 5670 MHz [134] (20.0 dBm) (no IR, radar detection)
        * 5680 MHz [136] (20.0 dBm) (no IR, radar detection)
        * 5700 MHz [140] (20.0 dBm) (no IR, radar detection)
        * 5745 MHz [149] (20.0 dBm) (no IR)
        * 5755 MHz [151] (20.0 dBm) (no IR)
        * 5765 MHz [153] (20.0 dBm) (no IR)
        * 5785 MHz [157] (20.0 dBm) (no IR)
        * 5795 MHz [159] (20.0 dBm) (no IR)
        * 5805 MHz [161] (20.0 dBm) (no IR)
        * 5825 MHz [165] (20.0 dBm) (no IR)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.

Wiphy phy0
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (20.0 dBm)
        * 2417 MHz [2] (20.0 dBm)
        * 2422 MHz [3] (20.0 dBm)
        * 2427 MHz [4] (20.0 dBm)
        * 2432 MHz [5] (20.0 dBm)
        * 2437 MHz [6] (20.0 dBm)
        * 2442 MHz [7] (20.0 dBm)
        * 2447 MHz [8] (20.0 dBm)
        * 2452 MHz [9] (20.0 dBm)
        * 2457 MHz [10] (20.0 dBm)
        * 2462 MHz [11] (20.0 dBm)
        * 2467 MHz [12] (20.0 dBm) (no IR)
        * 2472 MHz [13] (20.0 dBm) (no IR)
        * 2484 MHz [14] (20.0 dBm) (no IR)
Band 2:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (20.0 dBm) (no IR)
        * 5190 MHz [38] (20.0 dBm) (no IR)
        * 5200 MHz [40] (20.0 dBm) (no IR)
        * 5220 MHz [44] (20.0 dBm) (no IR)
        * 5230 MHz [46] (20.0 dBm) (no IR)
        * 5240 MHz [48] (20.0 dBm) (no IR)
        * 5260 MHz [52] (20.0 dBm) (no IR, radar detection)
        * 5270 MHz [54] (20.0 dBm) (no IR, radar detection)
        * 5280 MHz [56] (20.0 dBm) (no IR, radar detection)
        * 5300 MHz [60] (20.0 dBm) (no IR, radar detection)
        * 5310 MHz [62] (20.0 dBm) (no IR, radar detection)
        * 5320 MHz [64] (20.0 dBm) (no IR, radar detection)
        * 5500 MHz [100] (20.0 dBm) (no IR, radar detection)
        * 5510 MHz [102] (20.0 dBm) (no IR, radar detection)
        * 5520 MHz [104] (20.0 dBm) (no IR, radar detection)
        * 5540 MHz [108] (20.0 dBm) (no IR, radar detection)
        * 5550 MHz [110] (20.0 dBm) (no IR, radar detection)
        * 5560 MHz [112] (20.0 dBm) (no IR, radar detection)
        * 5580 MHz [116] (20.0 dBm) (no IR, radar detection)
        * 5590 MHz [118] (20.0 dBm) (no IR, radar detection)
        * 5600 MHz [120] (20.0 dBm) (no IR, radar detection)
        * 5620 MHz [124] (20.0 dBm) (no IR, radar detection)
        * 5630 MHz [126] (20.0 dBm) (no IR, radar detection)
        * 5640 MHz [128] (20.0 dBm) (no IR, radar detection)
        * 5660 MHz [132] (20.0 dBm) (no IR, radar detection)
        * 5670 MHz [134] (20.0 dBm) (no IR, radar detection)
        * 5680 MHz [136] (20.0 dBm) (no IR, radar detection)
        * 5700 MHz [140] (20.0 dBm) (no IR, radar detection)
        * 5745 MHz [149] (20.0 dBm) (no IR)
        * 5755 MHz [151] (20.0 dBm) (no IR)
        * 5765 MHz [153] (20.0 dBm) (no IR)
        * 5785 MHz [157] (20.0 dBm) (no IR)
        * 5795 MHz [159] (20.0 dBm) (no IR)
        * 5805 MHz [161] (20.0 dBm) (no IR)
        * 5825 MHz [165] (20.0 dBm) (no IR)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.
adam-infosec commented 7 years ago

Forget about me guys, I just realized that my hostapd.conf had been corrupted. I reinstalled and it worked.

blackHatMonkey commented 7 years ago

@frankjulien Thanks for opening an issue and providing all the information. There seems to be an error regarding hostapd. Can you run hostapd with the following configuration file:

interface=#CHANGE THIS
hw_mode=a
driver=nl80211
ssid=test
channel=40
ignore_broadcast_ssid=0

and see if the AP is created or post any errors you get 😄.

blackHatMonkey commented 7 years ago

@frankjulien I'm closing this issue because of inactivity. Feel free to re-open if needed 😄.

frankjulien commented 7 years ago

Thanks for the answer and sorry for the late response. I have modified the hostapd.conf file as suggested by @blackHatMonkey, but the exact same problem remains when using wifiphisher.

When running hostapd hostapd.conf, I get the following output:

root@Kali:/etc/hostapd# hostapd hostapd.conf
Configuration file: hostapd.conf
wlan0: IEEE 802.11 Configured channel (40) not found from the channel list of current mode (2) IEEE 802.11a
wlan0: IEEE 802.11 Hardware does not support configured channel
Could not select hw_mode and channel. (-3)
wlan0: interface state UNINITIALIZED->DISABLED
wlan0: AP-DISABLED 
wlan0: Unable to setup interface.
wlan0: interface state DISABLED->DISABLED
wlan0: AP-DISABLED 
hostapd_free_hapd_data: Interface wlan0 wasn't started
nl80211: deinit ifname=wlan0 disabled_11b_rates=0

UPDATE: After running iw reg set US, the command hostapd hostapd.conf works perfectly, but wifiphisher still gives me the same error.

blackHatMonkey commented 7 years ago

@anakin1028 Do you have any idea if we can do this in wifiphisher?

anakin1028 commented 7 years ago

Hi guys, from the output of iwlist we can see that all the 5G channels are tagged a NO_IR flag and this means that this adaptor cannot do the active radiation (i.e. beaconing, active probe). In other words, this adaptor cannot lunch hostapd since AP requires beaconing. (This is specified in 802.11d for regulatory.)

As a reference: https://superuser.com/questions/809282/wifi-5ghz-ap-mode-what-does-no-ir-means-and-can-i-bypass-it

I think wifiphisher currently only support 2.4G since we'll specify hw_mode=g in the configuration file.

blackHatMonkey commented 7 years ago

@anakin1028 Looking at the OP then why does it fail on 5GHZ AP selection?

anakin1028 commented 7 years ago

I guess during ap recognition stage @frankjulien selects the 5G AP.

def _create_ap_with_info(self, packet):
        """
        Create and add an access point using the extracted information
        :param self: An AccessPointFinder object
        :param packet: A scapy.layers.RadioTap object
        :type self: AccessPointFinder
        :type packet: scapy.layers.RadioTap
        :return: None
        :rtype: None
        """

        elt_section = packet[dot11.Dot11Elt]
        try:
            channel = str(ord(packet[dot11.Dot11Elt:3].info))
        except (TypeError, IndexError):
            return

From the above code we just copy this channel number and this may cause problem since we only hardcode hw_mode=g when create the hostapd configuration file.

frankjulien commented 7 years ago

Ok... not sure I understood everything you guys said up there. Is it a problem with my laptops' internal NIC (because of the NO_IR flag) or with wifiphisher that only supports 2.4Ghz networks?

I still don't understand why I can manually start hostapd using the hostapd hostapd.conf command while wifiphisher can't. Just to be sure, the adapter I mention in the hostapd.conf file (wlan0, in my case) is the one wifiphisher chooses as the AP interface (which is the internal NIC of my laptop)... This leaves wlan1 (my external USB adapter) as the jamming interface. This is the correct thing to do, right ?

Now I'm really not sure if this is relevant, but while doing tests with airbase-ng, I got the following output:

root@Kali:~/Desktop# airbase-ng -c 44 -e test wlan0
ioctl(SIOCSIWMODE) failed: Device or resource busy
12:38:43  Created tap interface at0
12:38:43  Trying to set MTU on at0 to 1500
12:38:43  Access Point with BSSID 20:68:9D:0E:B9:45 started.
read failed: Network is down
wi_read(): Network is down
Error: Got channel -1, expected a value > 0.
write failed: Network is down
wi_write(): Network is down
Error sending beacon!
read failed: Network is down
wi_read(): Network is down

Don't hesitate if you want me to test anything else.

Thank you for your time.

frankjulien commented 7 years ago

I just tested wifiphisher with two AWUS051NH v2 external USB adapters and successfully got passed the original error message. I guess I have to conclude that my internal NIC can't be used by hostapd for 5Ghz networks, right?

anakin1028 commented 7 years ago

From the output of hostapd I think you cannot manually lunch for the 5g channel by your internal card since the output shows the hostapd getting diaable, right?

No_IR means the adaptor cannot do the radiation on the given channel so I think you cannot use this internal card to lunch hodtapd.

The second you mentioned that you can use another card to run wifiphisher in 5g network. We need more info about this part. Can you post the file /tmp/hostapd.conf when wifiphisher is running? Just use your external card and select the 5g AP then post this file.

frankjulien commented 7 years ago

Here is the /tmp/hostapd.conf file while running wifiphisher with my external USB adapters :

interface=wlan1
beacon_int=100
ssid=TP-LINK_5086_5G
hw_mode=g
channel=44

Also, here is the /tmp/dhcpd.conf file:

no-resolv
interface=wlan1
dhcp-range=10.0.0.2,10.0.0.100,12h
address=/#/10.0.0.1

After doing a second test, I realized that although I get passed the original error message ('hostapd failed to lunch!'), no deauthentication happens when wifiphisher runs. This, despite the fact that both cards work perfectly with aircrack-ng.

frankjulien commented 7 years ago

Also, I have no idea why this is the case, but since this morning, while using the same NICs as when I wrote my original post, (wlan0 is my internal NIC and wlan1 is my external USB adapter) the output of iw list doesn't show the no IR tags anymore:

root@Kali:/etc/hostapd# iw list
Wiphy phy1
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.
Wiphy phy0
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.
anakin1028 commented 7 years ago

Yes you are right. Wifiphisher currently only deauth on 2G channels.

About the output of hostapd: I haven't test this combination (I.e. hw_mode=g and channel=44) so not sure if hostapd can run under this combination. Theoretically g mode only supports on 2G channels so it seems strange for me you can run hostapd under this configuration.

frankjulien commented 7 years ago

Ok, thank you for your time @anakin1028, it's been very helpful talking with you ;-)

anakin1028 commented 7 years ago

No problem :) For your last question: What's the mode of your adaptor/wlan1?(i.e. monitor or managed) can you post both iw dev and iw list again?

blackHatMonkey commented 7 years ago

@anakin1028 This is definitely a bug on our end. The two option that I could think of are:

  1. Exclude(not show to the user) any SSID that is running in 5GHZ mode using channel number(channel > 13)
  2. In case the SSID is running in 5GHZ mode randomly set a channel(1..13)
anakin1028 commented 7 years ago

@blackHatMonkey currently I prefer solution 1 since if the target AccessPoint is at 5GHz our deauth process cannot function correctly. If one day we decide to support 5G channels, we can remove this constraint then. I know there are some issues that you mentioned on the PRs. I'll take a look on them when I have more time.

@frankjulien @blackHatMonkey Another interesting thing about this issue is that since we only sniff on the 2G channels why can we hear the beacon that brings channel > 13. I can just guess it is implemented by the vendor intentionally to steer the clients to 5G channels... @frankjulien is that access point a dual band AP?

frankjulien commented 7 years ago

@anakin1028, Yes, my tests are done on a dual band AP.

As requested, here is the output for iw dev and iw list (wlan0 is the internal NIC and wlan1 is the external USB adapter). As you can see, the 'no IR' tag does not appear anymore, although these are the same cards I was using when I wrote the original post.

iw dev:

phy#3
Interface wlan1
    ifindex 24
    wdev 0x300000001
    addr 00:c0:ca:8d:ec:41
    type managed
    channel 44 (5220 MHz), width: 40 MHz, center1: 5230 MHz
    txpower 23.00 dBm
phy#0
Interface wlan0
    ifindex 3
    wdev 0x1
    addr 20:68:9d:0e:b9:45
    type managed
    channel 44 (5220 MHz), width: 40 MHz, center1: 5230 MHz
    txpower 23.00 dBm

iw list:

Wiphy phy3
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.

Wiphy phy0
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.

Just in case it can be helpful, here is the output, again, with wlan1 in monitor mode (wlan1mon). As you can see, the no IR tag is still absent.:

iw dev:

phy#3
Interface wlan1mon
    ifindex 25
    wdev 0x300000002
    addr 00:c0:ca:8d:ec:41
    type monitor
    channel 10 (2457 MHz), width: 20 MHz (no HT), center1: 2457 MHz
    txpower 30.00 dBm
phy#0
Interface wlan0
    ifindex 3
    wdev 0x1
    addr 20:68:9d:0e:b9:45
    type managed
    txpower 23.00 dBm

iw list:

Wiphy phy3
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x17e
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        RX STBC 1-stream
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 32767 bytes (exponent: 0x002)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-7, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.

Wiphy phy0
max # scan SSIDs: 4
max scan IEs length: 2257 bytes
max # sched scan SSIDs: 0
max # match sets: 0
max # scan plans: 1
max scan plan interval: -1
max scan plan iterations: 0
Retry short long limit: 2
Coverage class: 0 (up to 0m)
Device supports RSN-IBSS.
Supported Ciphers:
    * WEP40 (00-0f-ac:1)
    * WEP104 (00-0f-ac:5)
    * TKIP (00-0f-ac:2)
    * CCMP-128 (00-0f-ac:4)
    * CCMP-256 (00-0f-ac:10)
    * GCMP-128 (00-0f-ac:8)
    * GCMP-256 (00-0f-ac:9)
Available Antennas: TX 0 RX 0
Supported interface modes:
     * IBSS
     * managed
     * AP
     * AP/VLAN
     * monitor
     * mesh point
Band 1:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 1.0 Mbps
        * 2.0 Mbps (short preamble supported)
        * 5.5 Mbps (short preamble supported)
        * 11.0 Mbps (short preamble supported)
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 2412 MHz [1] (30.0 dBm)
        * 2417 MHz [2] (30.0 dBm)
        * 2422 MHz [3] (30.0 dBm)
        * 2427 MHz [4] (30.0 dBm)
        * 2432 MHz [5] (30.0 dBm)
        * 2437 MHz [6] (30.0 dBm)
        * 2442 MHz [7] (30.0 dBm)
        * 2447 MHz [8] (30.0 dBm)
        * 2452 MHz [9] (30.0 dBm)
        * 2457 MHz [10] (30.0 dBm)
        * 2462 MHz [11] (30.0 dBm)
        * 2467 MHz [12] (disabled)
        * 2472 MHz [13] (disabled)
        * 2484 MHz [14] (disabled)
Band 2:
    Capabilities: 0x2fe
        HT20/HT40
        SM Power Save disabled
        RX Greenfield
        RX HT20 SGI
        RX HT40 SGI
        TX STBC
        RX STBC 2-streams
        Max AMSDU length: 3839 bytes
        No DSSS/CCK HT40
    Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
    Minimum RX AMPDU time spacing: 2 usec (0x04)
    HT TX/RX MCS rate indexes supported: 0-15, 32
    Bitrates (non-HT):
        * 6.0 Mbps
        * 9.0 Mbps
        * 12.0 Mbps
        * 18.0 Mbps
        * 24.0 Mbps
        * 36.0 Mbps
        * 48.0 Mbps
        * 54.0 Mbps
    Frequencies:
        * 5180 MHz [36] (23.0 dBm)
        * 5190 MHz [38] (23.0 dBm)
        * 5200 MHz [40] (23.0 dBm)
        * 5220 MHz [44] (23.0 dBm)
        * 5230 MHz [46] (23.0 dBm)
        * 5240 MHz [48] (23.0 dBm)
        * 5260 MHz [52] (23.0 dBm) (radar detection)
        * 5270 MHz [54] (23.0 dBm) (radar detection)
        * 5280 MHz [56] (23.0 dBm) (radar detection)
        * 5300 MHz [60] (23.0 dBm) (radar detection)
        * 5310 MHz [62] (23.0 dBm) (radar detection)
        * 5320 MHz [64] (23.0 dBm) (radar detection)
        * 5500 MHz [100] (23.0 dBm) (radar detection)
        * 5510 MHz [102] (23.0 dBm) (radar detection)
        * 5520 MHz [104] (23.0 dBm) (radar detection)
        * 5540 MHz [108] (23.0 dBm) (radar detection)
        * 5550 MHz [110] (23.0 dBm) (radar detection)
        * 5560 MHz [112] (23.0 dBm) (radar detection)
        * 5580 MHz [116] (23.0 dBm) (radar detection)
        * 5590 MHz [118] (23.0 dBm) (radar detection)
        * 5600 MHz [120] (23.0 dBm) (radar detection)
        * 5620 MHz [124] (23.0 dBm) (radar detection)
        * 5630 MHz [126] (23.0 dBm) (radar detection)
        * 5640 MHz [128] (23.0 dBm) (radar detection)
        * 5660 MHz [132] (23.0 dBm) (radar detection)
        * 5670 MHz [134] (23.0 dBm) (radar detection)
        * 5680 MHz [136] (23.0 dBm) (radar detection)
        * 5700 MHz [140] (23.0 dBm) (radar detection)
        * 5745 MHz [149] (30.0 dBm)
        * 5755 MHz [151] (30.0 dBm)
        * 5765 MHz [153] (30.0 dBm)
        * 5785 MHz [157] (30.0 dBm)
        * 5795 MHz [159] (30.0 dBm)
        * 5805 MHz [161] (30.0 dBm)
        * 5825 MHz [165] (30.0 dBm)
        * 5835 MHz [167] (disabled)
        * 5845 MHz [169] (disabled)
        * 5855 MHz [171] (disabled)
        * 5865 MHz [173] (disabled)
Supported commands:
     * new_interface
     * set_interface
     * new_key
     * start_ap
     * new_station
     * new_mpath
     * set_mesh_config
     * set_bss
     * authenticate
     * associate
     * deauthenticate
     * disassociate
     * join_ibss
     * join_mesh
     * set_tx_bitrate_mask
     * frame
     * frame_wait_cancel
     * set_wiphy_netns
     * set_channel
     * set_wds_peer
     * probe_client
     * set_noack_map
     * register_beacons
     * start_p2p_device
     * set_mcast_rate
     * connect
     * disconnect
     * set_qos_map
     * Unknown command (121)
Supported TX frame types:
     * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
     * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
Supported RX frame types:
     * IBSS: 0x40 0xb0 0xc0 0xd0
     * managed: 0x40 0xd0
     * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * mesh point: 0xb0 0xc0 0xd0
     * P2P-client: 0x40 0xd0
     * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
     * P2P-device: 0x40 0xd0
software interface modes (can always be added):
     * AP/VLAN
     * monitor
valid interface combinations:
     * #{ AP, mesh point } <= 8,
       total <= 8, #channels <= 1
HT Capability overrides:
     * MCS: ff ff ff ff ff ff ff ff ff ff
     * maximum A-MSDU length
     * supported channel width
     * short GI for 40 MHz
     * max A-MPDU length exponent
     * min MPDU start spacing
Device supports TX status socket option.
Device supports HT-IBSS.
Device supports SAE with AUTHENTICATE command
Device supports low priority scan.
Device supports scan flush.
Device supports AP scan.
Device supports per-vif TX power setting
Driver supports full state transitions for AP/GO clients
Driver supports a userspace MPM
Device supports configuring vdev MAC-addr on create.
blackHatMonkey commented 6 years ago

This issue should be fixed now 😄 .