airodump-ng使用手册
选项:
-i, --ivs
捕捉WEP加密的包,忽略出IV之外的所有的包,保存为.ivs格式
airodump-ng wls35u1 -i -w captures
airodump-ng wls35u1 --i --write captures
-g, --gpsd
捕捉包中带有的gps坐标信息
airodump-ng wls35u1 --gpsd
-w <prefix>, --write <prefix>
将捕获的包写入文件,默认有四种格式 .cap, .csv, .kismet.csv, .kistmet.netxml。保存的默认路径是当前路径,prefix为文件前缀。
airodump-ng wls35u1 -w /home/captures
airodump-ng wls35u1 --write /home/captures
-e, --beacons
记录所有捕获到的信标,不加的情况只记录一个
-u <secs>, --update <secs>
适用于CPU处理能力较低的情况,设定屏幕显示的刷新间隔
airodump-ng wls35u1 -u 2
airodump-ng wls35u1 --update 2
--showack
显示握手包信息
-h
隐藏不在条件内的握手包信息
--berlin <secs>
如果AP或客户端的数据在secs时间内没有收到,从显示中除去。默认是120s
airodump-ng wls35u1 --berlin 15
-c <channel>[,<channel>[,...]], --channel <channel>[,<channel>[,...]]
按特定的信道跳跃,捕获数据包
airodump-ng wls35u1 -c 3
airodump-ng wls35u1 -c 3,2,4-5,7-11
-b <abg>, --band <abg>
按特定的信道规则跳跃,捕获数据包
a为:
36, 40, 44, 48, 52, 56, 60, 64, 100, 104, 108,
112, 116, 120, 124, 128, 132, 136, 140, 149,
153, 157, 161, 184, 188, 192, 196, 200, 204,
208, 212, 216,0
bg为:
1, 7, 13, 2, 8, 3, 14, 9, 4, 10, 5, 11, 6, 12, 0
abg为:
1, 7, 13, 2, 8, 3, 14, 9, 4, 10, 5, 11, 6, 12,
36, 40, 44, 48, 52, 56, 60, 64, 100, 104, 108,
112, 116, 120, 124, 128, 132, 136, 140, 149,
153, 157, 161, 184, 188, 192, 196, 200, 204,
208, 212, 216,0
airodump-ng wls35u1 -b abg
airodump-ng wls35u1 --band abg
-s <method>, --cswitch <method>
在多张网卡进行捕获时,规定各信道的跳跃方式:
0 (FIFO, default value)
1 (Round Robin)
2 (Hop on last)
airodump-ng wls35u1,wls35u2 -s 0
airodump-ng wls35u1,wls35u2 --cswitch 0
-r <file>
从pcap文件中读取数据捕获
airodump-ng wls35u1 -r captures.cap
-x <msecs>
Active Scanning Simulation (send probe requests and parse the
probe responses).
-M, --manufacturer
添加列manufacturer,显示AP网卡的制造商
airodump-ng wls35u1 -M
airodump-ng wls35u1 --manufacturer
-U, --uptime
添加列uptime,显示AP在线时间
airodump-ng wls35u1 -U
airodump-ng wls35u1 --uptime
-W, --wps
新增一列显示wps版本信息
airodump-ng wls35u1 -W
airodump-ng wls35u1 --wps
--output-format <formats>
输出文件类型: pcap, ivs, csv, gps, kismet, netxml。默认的类型为: pcap, csv, kismet, kismet-newcore.需与-w或--write配合使用
airodump-ng wls35u1 -w capture --output-format 'csv'
-I <seconds>, --write-interval <seconds>
输出文件刷新的时间间隔,默认为5s
--ignore-negative-one
移除右上角显示的信息'fixed channel <interface>: -1'
-f <msecs>
信道跳跃的时间间隔
airodump-ng wls35u1 -f 2000
-C <frequencies>
信道按频率(MHz)进行跳跃,最大信道频率10000MHz
airodump-ng wls35u1 -C 2412-2472,5180-5825
过滤选项:
-t <OPN|WEP|WPA|WPA1|WPA2>, --encrypt <OPN|WEP|WPA|WPA1|WPA2>
捕获特定加密方式的数据: '-t OPN -t WPA2'
airodump-ng wls35u1 -t WPA2
airodump-ng wls35u1 --encrypt WPA2
-d <bssid>, --bssid <bssid>
捕获规定bssid(ap mac)的数据
airodump-ng wls35u1 -d 88:25:93:C1:C2:FC
airodump-ng wls35u1 --bssid 88:25:93:C1:C2:FC
-m <mask>, --netmask <mask>
mac掩码选项
airodump-ng wls35u1 -d 88:25:93:C1:C2:FC -m FF:FF:FF:00:00:00
airodump-ng wls35u1 --bssid 88:25:93:C1:C2:FC --netmask FF:FF:FF:00:00:00
-a
不显示 (not associated) 标识的终端信息
airodump-ng wls35u1 -a
-N, --essid
捕获规定的essid(ap name)的数据
airodump-ng wls35u1 -N google
airodump-ng wls35u1 --essid google
-R, --essid-regex
Filter APs by ESSID using a regular expression.
INTERACTION
airodump-ng can receive and interpret key strokes while running. The
following list describes the currently assigned keys and supposed
actions:
a Select active areas by cycling through these display options:
AP+STA; AP+STA+ACK; AP only; STA only
d Reset sorting to defaults (Power)
i Invert sorting algorithm
m Mark the selected AP or cycle through different colors if the
selected AP is already marked
r (De-)Activate realtime sorting - applies sorting algorithm
everytime the display will be redrawn
s Change column to sort by, which currently includes: First seen;
BSSID; PWR level; Beacons; Data packets; Packet rate; Channel;
Max. data rate; Encryption; Strongest Ciphersuite; Strongest
Authentication; ESSID
SPACE Pause display redrawing/ Resume redrawing
TAB Enable/Disable scrolling through AP list
UP Select the AP prior to the currently marked AP in the displayed
list if available
DOWN Select the AP after the currently marked AP if available
If an AP is selected or marked, all the connected stations will also be
selected or marked with the same color as the corresponding Access
Point.
EXAMPLES
airodump-ng -c 9 wlan0mon
Here is an example screenshot:
-----------------------------------------------------------------------
CH 9 ][ Elapsed: 1 min ][ 2007-04-26 17:41 ][ BAT: 2 hours 10 mins ][
WPA handshake: 00:14:6C:7E:40:80
BSSID PWR RXQ Beacons #Data, #/s CH MB ENC CIPHER
AUTH ESSID
00:09:5B:1C:AA:1D 11 16 10 0 0 11 54. OPN
<length: 7>
00:14:6C:7A:41:81 34 100 57 14 1 9 11 WEP WEP
bigbear
00:14:6C:7E:40:80 32 100 752 73 2 9 54 WPA TKIP
PSK teddy
BSSID STATION PWR Rate Lost Frames
Probes
00:14:6C:7A:41:81 00:0F:B5:32:31:31 51 11-11 2 14 big‐
bear
(not associated) 00:14:A4:3F:8D:13 19 11-11 0 4 mossy
00:14:6C:7A:41:81 00:0C:41:52:D1:D1 -1 11-2 0 5 big‐
bear
00:14:6C:7E:40:80 00:0F:B5:FD:FB:C2 35 36-24 0 99 teddy
-----------------------------------------------------------------------
BSSID MAC address of the access point. In the Client section, a BSSID
of "(not associated)" means that the client is not associated
with any AP. In this unassociated state, it is searching for an
AP to connect with.
PWR Signal level reported by the card. Its signification depends on
the driver, but as the signal gets higher you get closer to the
AP or the station. If the BSSID PWR is -1, then the driver
doesn't support signal level reporting. If the PWR is -1 for a
limited number of stations then this is for a packet which came
from the AP to the client but the client transmissions are out
of range for your card. Meaning you are hearing only 1/2 of the
communication. If all clients have PWR as -1 then the driver
doesn't support signal level reporting.
RXQ Only shown when on a fixed channel. Receive Quality as measured
by the percentage of packets (management and data frames) suc‐
cessfully received over the last 10 seconds. It's measured over
all management and data frames. That's the clue, this allows you
to read more things out of this value. Lets say you got 100 per‐
cent RXQ and all 10 (or whatever the rate) beacons per second
coming in. Now all of a sudden the RXQ drops below 90, but you
still capture all sent beacons. Thus you know that the AP is
sending frames to a client but you can't hear the client nor the
AP sending to the client (need to get closer). Another thing
would be, that you got a 11MB card to monitor and capture frames
(say a prism2.5) and you have a very good position to the AP.
The AP is set to 54MBit and then again the RXQ drops, so you
know that there is at least one 54MBit client connected to the
AP.
Beacons
Number of beacons sent by the AP. Each access point sends about
ten beacons per second at the lowest rate (1M), so they can usu‐
ally be picked up from very far.
#Data Number of captured data packets (if WEP, unique IV count),
including data broadcast packets.
#/s Number of data packets per second measure over the last 10 sec‐
onds.
CH Channel number (taken from beacon packets). Note: sometimes
packets from other channels are captured even if airodump-ng is
not hopping, because of radio interference.
MB Maximum speed supported by the AP. If MB = 11, it's 802.11b, if
MB = 22 it's 802.11b+ and higher rates are 802.11g. The dot
(after 54 above) indicates short preamble is supported. 'e'
indicates that the network has QoS (802.11e) enabled.
ENC Encryption algorithm in use. OPN = no encryption,"WEP?" = WEP or
higher (not enough data to choose between WEP and WPA/WPA2), WEP
(without the question mark) indicates static or dynamic WEP, and
WPA or WPA2 if TKIP or CCMP or MGT is present.
CIPHER The cipher detected. One of CCMP, WRAP, TKIP, WEP, WEP40, or
WEP104. Not mandatory, but TKIP is typically used with WPA and
CCMP is typically used with WPA2. WEP40 is displayed when the
key index is greater then 0. The standard states that the index
can be 0-3 for 40bit and should be 0 for 104 bit.
AUTH The authentication protocol used. One of MGT (WPA/WPA2 using a
separate authentication server), SKA (shared key for WEP), PSK
(pre-shared key for WPA/WPA2), or OPN (open for WEP).
WPS This is only displayed when --wps (or -W) is specified. If the
AP supports WPS, the first field of the column indicates version
supported. The second field indicates WPS config methods (can be
more than one method, separated by comma): USB = USB method,
ETHER = Ethernet, LAB = Label, DISP = Display, EXTNFC = External
NFC, INTNFC = Internal NFC, NFCINTF = NFC Interface, PBC = Push
Button, KPAD = Keypad. Locked is displayed when AP setup is
locked.
ESSID The so-called "SSID", which can be empty if SSID hiding is acti‐
vated. In this case, airodump-ng will try to recover the SSID
from probe responses and association requests.
STATION
MAC address of each associated station or stations searching for
an AP to connect with. Clients not currently associated with an
AP have a BSSID of "(not associated)".
Rate This is only displayed when using a single channel. The first
number is the last data rate from the AP (BSSID) to the Client
(STATION). The second number is the last data rate from Client
(STATION) to the AP (BSSID).
Lost It means lost packets coming from the client. To determine the
number of packets lost, there is a sequence field on every non-
control frame, so you can subtract the second last sequence num‐
ber from the last sequence number and you know how many packets
you have lost.
Packets
The number of data packets sent by the client.
Probes The ESSIDs probed by the client. These are the networks the
client is trying to connect to if it is not currently connected.
The first part is the detected access points. The second part is a list
of detected wireless clients, stations. By relying on the signal power,
one can even physically pinpoint the location of a given station.
airodump-ng使用手册的更多相关文章
- Linux使用手册-vi使用手册
vi使用手册 VI是unix上最常用的文本编辑工具,作为unix软件测试人员,有必要熟练掌握它. 进入vi的命令 vi filename :打开或新建文件,并将光标置于第一行首 vi +n filen ...
- WHM使用手册by lin
WebHost Manager 11使用手册(WHM使用手册) 本手册翻译自cpanel官方文档. 本翻译中文版本版权归美国主机侦探所有,未经允许,禁止复制. Overview(概述) 本用户手册主要 ...
- Linux帮助手册(man)
Linux的帮助文档 在我们使用Linux的过程中,都会遇到这样那样的问题,一般我们在计算机能连上网的情况下会进行百度或Google解决问题,但是并不是所有文题都能在网上很快得到答案.万一我们是在没有 ...
- Spring Security 5.0.x 参考手册 【翻译自官方GIT-2018.06.12】
源码请移步至:https://github.com/aquariuspj/spring-security/tree/translator/docs/manual/src/docs/asciidoc 版 ...
- hydra-microservice 中文手册(3W字预警)
Hydras 是什么? Hydra 是一个 NodeJS 包(技术栈不是重点,思想!思想!思想!),它有助于构建分布式应用程序,比如微服务. Hydra 提供服务发现(service discover ...
- FREERTOS 手册阅读笔记
郑重声明,版权所有! 转载需说明. FREERTOS堆栈大小的单位是word,不是byte. 根据处理器架构优化系统的任务优先级不能超过32,If the architecture optimized ...
- JS魔法堂:不完全国际化&本地化手册 之 理論篇
前言 最近加入到新项目组负责前端技术预研和选型,其中涉及到一个熟悉又陌生的需求--国际化&本地化.熟悉的是之前的项目也玩过,陌生的是之前的实现仅仅停留在"有"的阶段而已. ...
- 转职成为TypeScript程序员的参考手册
写在前面 作者并没有任何可以作为背书的履历来证明自己写作这份手册的分量. 其内容大都来自于TypeScript官方资料或者搜索引擎获得,期间掺杂少量作者的私见,并会标明. 大部分内容来自于http:/ ...
- Redis学习手册(目录)
为什么自己当初要选择Redis作为数据存储解决方案中的一员呢?现在能想到的原因主要有三.其一,Redis不仅性能高效,而且完全免费.其二,是基于C/C++开发的服务器,这里应该有一定的感情因素吧.最后 ...
- JS魔法堂:不完全国际化&本地化手册 之 实战篇
前言 最近加入到新项目组负责前端技术预研和选型,其中涉及到一个熟悉又陌生的需求--国际化&本地化.熟悉的是之前的项目也玩过,陌生的是之前的实现仅仅停留在"有"的阶段而已. ...
随机推荐
- python --- json模块和pickle模块详解
json:JSON(JavaScript Object Notation, JS 对象标记) 是一种轻量级的数据交换格式(用于数据序列化和反序列化).(适用于多种编程语言,可以与其他编程语言做数据交换 ...
- SqlServer和Oracle中一些常用的sql语句3 行列转换
--217, SQL SERVER SELECT Cust_Name , MAX(CASE WHEN Order_Date ='2009-08-01' THEN AR END) "2009- ...
- [置顶]
一个demo学会c#
学习了c#4.5高级编程这本书,自己喜欢边学边总结边写demo,所以写了这篇文章,包含了大部分的c#编程知识.让你一个demo掌握c#编程,如果有问题可以留言. 此demo主要包括五个文件:Stude ...
- dotweb框架之旅 [三] - 常用对象-HttpServer
dotweb属于一个Web框架,希望通过框架行为,帮助开发人员快速构建Web应用,提升开发效率,减少不必要的代码臃肿. dotweb包含以下几个常用对象: App(dotweb) App容器,为Web ...
- SQL server 数据库备份大
首先简单的介绍一下Sql server 备份的类型有: 1:完整备份(所有的数据文件和部分的事务日志文件) 2:差异备份(最后一次完成备份后数据库改变的部分) 3:文件和文件组备份(对指定的文件和文件 ...
- C# 复制列表
本文:如何复制一个列表 最简单的方法是 foreach foreach(var temp in a) { b.Add(temp); } 有没一个简单的方法? using System.Linq; va ...
- win10 uwp 隐私声明
本文讲的是如何去写隐私声明. 垃圾微软要求几乎每个应用都要有隐私声明,当然如果你不拿用户信息的话,那么用户声明是一个URL,我们应该把应用声明放在哪? 其实我们简单方法是把隐私声明Privacy Po ...
- C 实现可变参数
C中可以借助va_list实现可变参数: va_start:使用传入的可变参数的第一个变量初始化va_list va_arg:获取当前可变参数,每次调用时会将指针向后移 va_end:结束 利用这个机 ...
- LINUX 笔记-mv命令
常用参数: -f :force强制的意思,如果目标文件已经存在,不会询问而直接覆盖 -i :若目标文件已经存在,就会询问是否覆盖 -u :若目标文件已经存在,且比目标文件新,才会更新
- viewpager的滑动
在一个已经是月黑风高快下班的时刻了,我们产品突然通知我们开会,要添加一个功能,他闲来无聊随便戳了戳facebook,说点开联系人的那个横向滑动的卡片式的效果不错,让我们在我们的app里添加这个效果,我 ...