OpenWrt Forum Archive

Topic: White Russian (0.9) and Kismet on a WRT54GL v1.1

The content of this topic has been archived on 23 Apr 2018. There are no obvious gaps in this topic, but there may still be some posts missing at the end.

Hey guys,

I know White Russian is a dead branch but I'm new to Linux and OpenWRT and am wondering if I'm doing something wrong, or if this is a known limitation with the broadcom driver.  I got my WRT54GL last night and have been reading and tinkering non-stop.  Anyway, I'm hoping some people still read this forum and feel like helping out. smile

I have my WRT65GL running in Client (Managed) mode and running the kismet_server and kismet_client on it.  I have kismet logging to a share on an XP laptop that's wired to the Linksys.

What I noticed when looking through the dump file with WireShark is that there are no data packets in the wireless captures.  It's all Layer 2 connection information (Beacon Frames, Probe Requests, Acknowledgements). 

I got my wife to connect to a wireless router and she did some IM'ing, web browsing, watched some streaming content and nothing was showing up in the .dump file.

I also tried playing with the kismet.conf file, reading all the docs I could find on kismet and OpenWRT, and I'm feeling stuck. 

I found someone else asking the same question at the kismet forums but their answer didn't help me enough.   They said kismet will log what the driver gives it.  Well, that leads me to believe it might be a driver issue.  Since the driver came with the White Russian 0.9 deliverable, I'm assuming everyone has this problem.

Have any of you guys run into this?  Did you find a way around it?  I'd like to be able to capture data packets over wireless as well as the connection packets.

Thanks in Advance!  smile

P.S. I'm downloading a VM so I can learn how to compile linux binaries if required, but I'm very new to Linux (the closest experience I have was using DOS on a 386/486 LOL) so please don't be too mean.  smile

It looks like switching from "source=wrt54g,eth1,wireless" to "source=wrt54g,eth1:prism0,wireless" has added some data packets.  I'm still not seeing data on an unprotected wireless connection (that I expected to see) but now I'm seeing data showing up for a secured wireless AP.  I'm not sure if it's real data or if it's due to me adding the noiselog=true setting in the kismet.conf file.  It's encryped, so I can't tell if it's garbage or real data.

Strange thing...  As stated in my previous message, I'm seeing some data packets now.  However, I'm not seeing data packets for a wide open unprotected wireless connection.  Kismet even alerts that my wifes computer is suspicious because she's probing networks but never participating:

ALERT: Suspicious client [insert MAC address here] - probing networks but never participating.

But she's watching movies over the internet, web browsing, and playing online video games.  I should be able to see http traffic, etc. but it's not showing up.

This leads me to believe the driver isn't passing all the information down to kismet.  Anyone else seeing this or have ideas on what the next step should be for troubleshooting this?

The discussion might have continued from here.