*

Welcome, Guest. Please login or register.

Get your own OLPC - Buy an XO laptop on eBay!
Pages: [1]
Print
Author Topic: Network packet sniffing with wireshark, tcpdump or alike  (Read 8115 times)

Network packet sniffing with wireshark, tcpdump or alike

tomvanbraeckel
Commenter

Posts: 5


December 27, 2007, 11:45:56 PM

Has anyone tried installing a sniffer like wireshark or tcpdump on the XO ?

If so, how did you do it ? Could you just do a: yum install wireshark at the command line ?
Logged

#1 Re: Network packet sniffing with wireshark, tcpdump or alike

patnukem
Contributor
*
Posts: 35


December 28, 2007, 01:04:40 AM

i just got driftnet to work i installed dependency

rpm -i http://ftp://ftp.pbone.net/mirror/ftp.turbolinux.com/pub/TurboLinux/Product/ia32/Server/6.5/install/TurboLinux/RPMS/libungif-4.1.0b1-4.i386.rpm

then

rpm -i http://ftp://ftp.pbone.net/mirror/download.fedora.redhat.com/pub/fedora/linux/updates/7/i386/driftnet-0.1.6-18.20040426cvs.fc7.i386.rpm

then I ran with no results but ran again with

driftnet -i eth0

and it worked great.  not quite wireshark, but my favorite program for checking what pictures people on your own network are looking at,  good for watching youngsters lol.
 I did notice after several pictures it will stop and requires a restart.  I wonder if there is an easy way around this if you would want to leave on longer.  This is the only problem I could find with it. 
« Last Edit: December 28, 2007, 02:15:24 AM by patnukem » Logged

#2 Re: Network packet sniffing with wireshark, tcpdump or alike

tomvanbraeckel
Commenter

Posts: 5


December 28, 2007, 01:17:20 AM

Aha that's interesting - it also gives me good hope on running Wireshark...
Logged

#3 Re: Network packet sniffing with wireshark, tcpdump or alike

cmonkey
Senior Contributor
**
Posts: 148



WWW
December 28, 2007, 11:08:30 AM

I haven't tried it yet, but tcpdump apparently works http://wiki.laptop.org/go/Wireless#Capturing_wireless_traffic_on_the_xo
Logged

#4 Re: Network packet sniffing with wireshark, tcpdump or alike

xoring
Contributor
*
Posts: 39


December 28, 2007, 11:17:45 AM

I haven't tried it yet, but tcpdump apparently works http://wiki.laptop.org/go/Wireless#Capturing_wireless_traffic_on_the_xo

More than Wireshark, I'm hoping for Kismet on the XO. Wireshark is great, but Kismet is better for troubleshooting wireless networks (which I do frequently).
Logged

#5 Re: Network packet sniffing with wireshark, tcpdump or alike

Gollumer
Contributor
*
Posts: 61


December 28, 2007, 05:25:57 PM

I haven't tried it yet, but tcpdump apparently works http://wiki.laptop.org/go/Wireless#Capturing_wireless_traffic_on_the_xo

More than Wireshark, I'm hoping for Kismet on the XO. Wireshark is great, but Kismet is better for troubleshooting wireless networks (which I do frequently).

Struggling with some compiler problems... I may just try stealing them from another PC and doing the old manual install...
Logged

#6 Re: Network packet sniffing with wireshark, tcpdump or alike

Shazbot
Commenter

Posts: 14


January 24, 2008, 03:03:14 AM

I tried running tcpdump using the instructions on the wiki, but when I type
echo $TRAFFIC_MASK > /sys/class/net/eth0/lbs_rtap
I get a permission denied.  I've tried running in both su and su - modes, anyone got any ideas?
Logged

#7 Re: Network packet sniffing with wireshark, tcpdump or alike

bfayette
Commenter

Posts: 29


January 24, 2008, 06:40:18 AM

yum install wireshark_gnome

will do it. Seems to work OK.
Logged

#8 Re: Network packet sniffing with wireshark, tcpdump or alike

Shazbot
Commenter

Posts: 14


January 24, 2008, 10:07:13 AM

yum install wireshark_gnome

will do it. Seems to work OK.

will that get libs_rtap working or just get wireshark working on the XO?
Logged

#9 Re: Network packet sniffing with wireshark, tcpdump or alike

bfayette
Commenter

Posts: 29


January 24, 2008, 02:27:13 PM

What is libs_rtap?
Logged

#10 Re: Network packet sniffing with wireshark, tcpdump or alike

eeddccdd
Commenter

Posts: 22


January 27, 2008, 03:48:50 PM

It's not libs_rtap, it's libertas_rtap. rtap0 is the device you presently need to call up, instead of eth0 or msh0, when you want to run in promiscuous mode, because for some reason to do with the Marvell, we're not yet able to just set eth0 mode monitor.

Anyone who understands this, feel free to explain, because I'm a noob.

If you're talking about rtap0, I guess you must have been doing research on olpc-wiki? WATCH OUT! I tried researching this, and when I tried to implement it, I fried the whole machine. I had to re-flash the OS, because the xo just went nuts.

yum install wireshark-gnome works fine. But for now, I'm NOT going to play with Wireshark in promiscuous mode. From what I've read, the developers are working on away to get rid of that whole rtap kludge, and it'll get fixed in a firmware update to come.

I am a noob, though, so I'd love to see someone with substantially more of a clue than me wade in and explain all.
Logged
Pages: [1]
Print
Jump to:  

Members
Total Members: 2406
Latest: sembik
Stats
Total Posts: 31943
Total Topics: 3843
Online Today: 28
Online Ever: 238
(April 18, 2011, 09:48:50 PM)
Users Online
Users: 0
Guests: 10
Total: 10