Question:Jpcap ?

Can I capture packets from a WiFi (802.11) network interface in windows XP by using Jpcap?
can i have some tutorials on this subject?
rbaianAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

grsteedCommented:
From the FAQ at this site, http://netresearch.ics.uci.edu/kfujii/jpcap/doc/index.html

Q: Can I capture packets from a WiFi (802.11) network interface?

A: The answer depends on what Operating System you are running and which WiFi devices your system has. On Windows, you may not be able to capture packets from some WiFi devices. Linux or BSD may have higher probability of supporting packet capturing using WiFi devices.

Jpcap development site.
http://sourceforge.net/projects/jpcap

I would say, give it a try. Normally you tell the program which interface to sniff so you should be able to point it to your WiFi card.

Have you considered other sniffer software like Ethereal.  http://www.ethereal.com/
lots of good info in their Documentation page.

Gary
marce_litoCommented:
i read somewhere that you can capture traffic from a wireless link if you bridge (www.microsoft.com/windowsxp/using/networking/expert/crawford_02april22.mspx) your wireless adapter with a wired adapter... haven't tried it personally, but it should work...
marce_litoCommented:
btw, ethereal is a great sniffer, and runs on *nix and windows... it's just great software
rbaianAuthor Commented:
thank you all,,,,

i think Gary give me a partial answer to my question but i need some tutorials in Jpcap.

grsteedCommented:
Couldn't find a tutorial specific to Jpcap.  It's probably very similar to the many other programs out there. They usually allow you to specify an interface to monitor, start/stop packet capture, display capture various ways, filter based on protocol/source and destination address/packet type, and allow you to import/export data.

The hardest part is understanding what you capture. Decoding packets is not for the faint of heart. There are many aspects to it like, connection setup and maintenance, DNS queries, broadcasts, Network Applications (mail, browsing, ftp, chat) and many others, all using their own protocols and ports. It's a very deep subject. Here's a good link on Network Protocols from IBM that explains how it all works. It's a PDF with 900+ pages.

http://www.redbooks.ibm.com/pubs/pdfs/redbooks/gg243376.pdf

A good place to start is just monitor your connection for a few minutes and look at what you catch. Some simple things to capture. Browse to a website and look at what it took to do that. Ping an address on your network. Release and Renew you IP.  Connect to a network share.

Like I said, there's a lot to learn in this area. Take it in baby steps. You can always post here for help understanding what you see.

Gary

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Networking

From novice to tech pro — start learning today.