
ssidsniff is a tool that helps with reconaissance of wireless activity. It 
listens passively to a wireless network interface and creates a list of
networks, their members and other important data. To achieve this, it
requires a wireless card that is able to deliver IEEE 802.11 packets in 
so called monitor mode. ssidsniff then uses the 802.11 packet header as 
well as other packet contents to display an interactive view of available
wireless networks.

This tool is currently developed on Linux, and works best on it.

Features:
 - Easy to use top(1) like interface
 - Lightweight on system resources
 - Can run multiple instances simultaneously
 - Enable/disable wireless monitor mode automatically
 - Embedded channel hopper
 - Sort networks by various criteria: packets per second, number of 
   data packets and so on
 - Capture selected sources (or any data sources) to libpcap compatible
   capture files for further manipulation
 - Offer a strings(1) like feature for cursory glance of recent
   printable packet contents
 - Audio notifications of wireless activity for hands free operation

Tested hardware, in order of recommendation:
 Engenius Senao NL-2511
 Lucent Orinoco silver, gold
 Intersil (Prism 2)
 Intel ipw2100
 Atheros AR5212
 Cisco PCM-340, PCM-350

Comments: 
If possible, install version 0.9 or higher of libpcap. This version
allows for setting the link discipline of the wireless adapter. If
that function is not available, ssidsniff will simply use whatever
link discipline the adapter is in. For Debian etch, install
libpcap0.8-dev.

The program will attempt to automatically bring the interface up and
switch it to monitor mode. Sometimes this fails because the driver
doesn't support it; you will see a warning in that case.

ssidsniff tries to extract per-packet signal strength information for 
display. Only some network card drivers currently support this feature 
in a standardized way, but you should expect this situation to improve 
with time as interfaces and APIs mature.

Usage:
Unpack and compile the software, a standard configure script is supplied.
You should end up with an executable called ssidsniff.

Start ssidsniff as root: 
shell# ./ssidsniff -i <interface_name>

Online help is accessible via the 'h' key. 'q' quits.


Atheros support for Debian etch:
The atheros driver is included in source form. To compile it, follow the
steps below. Please note that if you upgrade your kernel this will need
to be redone.

# apt-get install madwifi-source
# m-a prepare
# m-a a-i madwifi
# wlanconfig ath0 destroy
# wlanconfig ath0 create wlandev wifi0 wlanmode monitor
# echo 803 > /proc/sys/net/ath1/dev_type

 * Only 802.11 headers:  echo '801' > /proc/sys/net/ath0/dev_type
 * Prism2 headers: echo '802' > /proc/sys/net/ath0/dev_type
 * Radiotap headers: echo '803' > /proc/sys/net/ath0/dev_type
 * Atheros Descriptors: echo '804' > /proc/sys/net/ath0/dev_type 

$Id: README,v 1.12 2007-06-26 23:40:02 kos Exp $
