HolidayBuyer's Guide

Networking & Wireless forum

Question

I'm not getting the needed packets wih Wireshark

by pahunrepublic / May 30, 2012 4:38 AM PDT

I am testing wireshark for learning purposes. I wanted to try out a tutorial that hacks a facebook account stealing cookie information. I couldn't manage to hack my facebook account because wireshark is sending me truncated packets that I can't get cookie info out of.
**This topography of the network**: my desktop PC is connected to the Internet to a hub (D-LINK router) via LAN (ethernet cable). I have a notebook connected to Internet via Wi-Fi to the same hub (D-LINK router). I access facebook on my notebook on WIN XP OS. I monitor the packets with wireshark on my desktop PC on Ubuntu 12.04 OS. I only get worthless truncated cookie information. Why is that?
My capture interfaces are:
- eth0
- Pseudo device that captures on all interfaces
- USb1
- USB 2
- lo

I tried to capture on all interfaces (except usb 1, 2) but the same thing. I **can't get cookie information from my notebook**. I only get NBNS, DNS, Browser, IGMP, SSDP protocol type of packets. I get some HTTP but not facebook cookie with 'datr' line.
It is just anoying. It seems so easy in the tutorial.
Anyone could help me with this?

Discussion is locked
You are posting a reply to: I'm not getting the needed packets wih Wireshark
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: I'm not getting the needed packets wih Wireshark
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

All Answers

Collapse -
Answer
Router monitor
by bill012 / May 30, 2012 10:37 PM PDT

Wireshark is hard to learn when you try to start on the most advanced form of captures as a first project.

Your key problem is the capture of the wireless packets not the wireshark.

Start the easy way and capture the packets directly on the notebook you are surfing facebook from. This will let you see what the capture is suppose to look like.

Most people start by capturing wired ports but you need a special switch/router for that. You can buy just about any old cisco/hp/3com commercial switch for less than $20 and they have features called mirror or monitor ports on them.

Capture of wireless is a huge challenge. Problem number 1 is you need a wireless card that has the ability to be put in promiscuous mode. Problem number 2 is you cannot run on windows other than 1 card, microsoft has disabled the ability to set the promiscuous option. Problem number 3 is you need special software to set all the parameters in the card like channel numbers and bands etc.

Since you already have ubuntu you could load all these tools but it is a pain. The easy way is to load the prebuilt system call BACKTRAK. This has all the common device drivers already installed. It has every tool you could ever want but the key ones are AIRMON-NG and of course wireshark.

I will leave it to you to read all the details.

Collapse -
I have bactrack 5 installed
by pahunrepublic / June 1, 2012 1:09 AM PDT
In reply to: Router monitor

Thanx for the answer. I got BACKTRACK installed, yes it has many pretty tools but I have to learn those.

Collapse -
I encountered someone trying to do this.
by R. Proffitt Forum moderator / June 7, 2012 7:33 AM PDT

But they could not be helped. Why? They refused to get the card suggested by others. I guess they were still on the first lesson.
Bob

Popular Forums
icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

The Samsung RF23M8090SG

One of the best French door fridges we've tested

A good-looking fridge with useful features like an auto-filling water pitcher and a temperature-adjustable "FlexZone" drawer. It was a near-flawless performer in our cooling tests.