User`s guide
(C) 2003 Airscanner Corp. http://www.airscanner.com
nature of networking, this would wreck havoc on any attempted communication sessions. To
make this even more complicated, sniffing a wireless network in passive mode requires special
drivers, or at the minimum a patch to existing drivers.
3. Practical Sniffing
Now that you understand the many facets of sniffing, it is time to take a look at how you can
benefit from Airscanner Mobile Sniffer™. In addition, we have included a section on Ethereal to
help you prepare for future analysis of collected data from Airscanner Mobile Sniffer™. With
Ethereal, you will be able to quickly analyze collected data and drill down on potential network
problems.
3.1 Airscanner Mobile Sniffer™
URL: www.airscanner.com
Supported Platforms: Windows CE 3.0
3.1.1 Description
With the current trend toward mobile computing, Airscanner has released a sniffer
potentially capable of operating on any PocketPC device that supports the use of a WNIC. This
sniffer not only allows its user the freedom to roam independent of wires, but since it operates
on a pocket PC, a user can sniff the airwaves from the palm of her hand. Using this sniffer is as
easy as hitting one button, which will then start the sniffing process. Data is captured in Ethereal
format, which is one of the most popular formats currently used by security professionals.
In addition to basic sniffing, Airscanner Mobile Sniffer™ includes a fairly robust filtering
feature based on the OFDM language. With a filtering enabled, a user can quickly get access to
the data that is most important to them. This eliminates the need to waddle through hundreds, if
not thousands of packets just to locate a single byte of data. However, due to the limited screen
size of most pocket PC devices and other usability issues that most mobile devices have, the
ability to save and review packets in Ethereal makes Airscanner an excellent peripheral sniffer
for any administrator.
3.1.2 Requirements
The Mobile Sniffer does have several requirements before it will run correctly. These
include the following:
• Pocket PC operating system.
• Installation of operational wireless network adapter.
• Installation of proper drivers.
If any of these items are not met, Airscanner Mobile Sniffer™ will not install, or it will run
incorrectly. Symptoms of a problem include obvious error messages, program crashes, or the
lack of promiscuous mode during an otherwise normal sniffing session. If you do have a
problem, be sure to verify that your wireless network card is a Prism2 based card and that you
have the correct and intended drivers for your WNIC (e.g., improperly using a Linksys WPC11