• Join
  • Sign In with my.TI Login
Texas Instruments
  • Products
  • Applications
  • Tools & Software
  • Support & Community
  • Sample & Buy
  • About TI
Sample & Purchase Cart Sample & Purchase Cart
  • Search
  • Advanced
TI E2E™ Community
  • Support Forums
  • Blogs
  • Groups
  • Videos
  • 简体中文
  • More ...
TI Home » TI E2E Community » Support Forums » Low Power RF & Wireless Connectivity » WLAN Applications Forum » TiWi01-R2 sniffer
Share
Low Power RF & Wireless Connectivity
  • Forums
  • Announcements
  • Files
  • E2E Wiki
Options
  • Subscribe via RSS

Forums

TiWi01-R2 sniffer

This question is not answered
Luca Bencini
Posted by Luca Bencini
on Oct 07 2011 10:28 AM
Prodigy20 points

Dear all,

I am Luca Bencini an employee of Tecnosistemi S.p.A.

 

I have to realize an IEEE 802.11 b/g/n sniffer. For this purpose I am looking for a wifi transceiver that support the "monitor mode". The "monitor mode" allows a wireless network interface to monitor all traffic received from a wireless network.

 

Does TiWi01-R2 support monitor mode? How can I configure it?

 

Thank you for your help.

 

Luca Bencini

Report Abuse
  • Reply
You have posted to a forum that requires a moderator to approve posts before they are publicly available.
All Replies
  • Eyal a
    Posted by Eyal a
    on Oct 09 2011 17:17 PM
    Genius9240 points

    Hi Luca,

    The WL1271 FW does not support monitor mode. TI has licensed the FW to several partners that may be interested in helping you to implement a sniffer. If you want me to help you get it touch with them, please send out your contact information.

    Regards,

    Eyal

     

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • FS
    Posted by FS
    on Nov 07 2011 05:56 AM
    Prodigy100 points

    Hello Eyal,

    I prefer not to disclose my company name right here and now, but if there is a way to discuss with you in private it would be a pleasure to give you more details.

    I am also hoping to realize a 802.11 sniffer using WL1271/WL1273 and feel disappointed to read that its FW does not support monitor mode...

    I am not sure I exactly understand what you replied to Luca: does this mean that under some conditions it is possible to have access to WL1271 FW source code in order to adapt it?

    Could you help me going further in this direction?

    Thank you very much in advance for your help.

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • FS
    Posted by FS
    on Nov 16 2011 04:54 AM
    Prodigy100 points

    Hello again Eyal,

    I am coming back to you regarding this.

    I wish we could find a way to go on. Is there another way I can contact you?

    Thank you very much in advance,

    Best regards.

    WL1271 firmware.bin Monitor Mode
    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Eyal a
    Posted by Eyal a
    on Nov 16 2011 05:50 AM
    Genius9240 points

    Hi,

    I got your email which i will respond

    Regards,

    Eyal

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Usman Ali
    Posted by Usman Ali
    on Dec 12 2011 11:35 AM
    Prodigy10 points
    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Eyal a
    Posted by Eyal a
    on Dec 13 2011 14:13 PM
    Genius9240 points

    Hi,

    I verified that with Marketing and got their advice. the way to get that contact is to contact TI Local distributer in your Aria and they will be able to help

    Regards,

    Eyal  

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • FS
    Posted by FS
    on Dec 15 2011 04:29 AM
    Prodigy100 points

    Hello Eyal,

    Thank you for your reply.

    Could it be possible that you give us the list of companies that could help us more directly with the firmware? Maybe some of the ones you mentioned in your first post above?

    Please note that my company already signed a NDA with TI.

    Best regards.

    FS

     

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Elad Raz92038
    Posted by Elad Raz92038
    on Dec 25 2011 03:22 AM
    Expert1580 points

    Hi FS,

    There are 2 "types" of FW:

    • Open source project (Internally called NLCP) which you can download via git. 
    • MCP driver sources + firmware
    The firmwares are slightly changed but mostly the upper interface has changed. Anyway, there are 2 registers called "RX_CONFIG" and "RX_FILTER"
    In the MCP driver+firmware you can change RX filters to listen to *everything* that the reciever gets (RX_CFG_PROMISCUOUS). So a change in only the driver code and it's state machine can give you the desire "monitor mode". Note that you will have to by-pass all "connection state machines" to open the radio to listen, and changing the radio band, making sure the FW is in Active mode.

    I do see the rx-filters registers in the NLCP driver but for some reason they are commented out. Maybe trying to forcely change these value will also do the trick. 

    Elad

    - Elad Raz

    CTO

    www.integrity-project.com

    PROMISCUOUS wl1273 1273 1283 monitor mode
    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Bernard Seller
    Posted by Bernard Seller
    on Dec 29 2011 12:36 PM
    Intellectual430 points

    Would this provide

           - all packets for all BSSIDs ?

            - or just all the packets for the BSSID that I am part of ?

    ( My understanding of the wireless promiscuous mode is that it would provide all the packets for the BSSID that I am part of)

    Has any tried this and sucessfully got the equivalent of the MONITOR mode running on a wl1271?

    thanks

    Bernard

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Elad Raz92038
    Posted by Elad Raz92038
    on Jan 01 2012 03:00 AM
    Expert1580 points

    All packets that are in the same band. The HW will not drop any packet out. This is risky, since the memblocks in the FW will be block very very fast...

    So the packet poll rate suppose to be higher.

    I never tried it, and I'm not sure that anyone tried it out.

    Elad.

    - Elad Raz

    CTO

    www.integrity-project.com

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Bernard Seller
    Posted by Bernard Seller
    on Jan 03 2012 14:44 PM
    Intellectual430 points

    I was asking if had been tried because my undestanding is

    that this approach works on the wl1251, but the wl1271 has more "intelligence" and there might not be the right hooks to completely disable the filtering so we can see all packets for all bssids (although some might be encrypted of course) for a given channel

    Bernard

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Elad Raz92038
    Posted by Elad Raz92038
    on Jan 04 2012 04:10 AM
    Expert1580 points

    Yep, I look at the FW code, in wl12xx (open-source driver) there is "link" classification for RX, and there are couple of places there to change:

    1. Encrypted frame are being decrypted by the FW and thrown away if there is no key (and we don't have it)
    2. The MAC address are being classified to link-ids, and wrong classification will also mean that the packet is being dispose.
    So you need to change the FW as well, adding a "promiscuous" command that will classified everything as link 0 (managment) 
    Elad.

    - Elad Raz

    CTO

    www.integrity-project.com

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • FS
    Posted by FS
    on Jan 06 2012 03:48 AM
    Prodigy100 points

    Hello Elad,

    Thank you very much for the very valuable information you posted recently. 

    I am also very interested in enabling wl127x monitor mode but so far all my attempts were unsuccessful. Thanks to you I think I better see why now...

    There is something I didn't get: you wrote : "So you need to change the FW as well".  I would be super happy to do so, but how can I get access to the firmware sources?

    I think that I searched quite thoroughly, but there is no way to get something else than .bin files for firmware...

    Could you help me with this? 

    Thank you very much in advance.

    FS 

    Monitor Mode firmware sources promiscuous mode
    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • Elad Raz92038
    Posted by Elad Raz92038
    on Jan 07 2012 07:45 AM
    Expert1580 points

    You can't get any access to TI FW. It's not a public code.

    You can use external design house (such as ourselves).

    - Elad.

     

    - Elad Raz

    CTO

    www.integrity-project.com

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
  • FS
    Posted by FS
    on Jan 09 2012 03:20 AM
    Prodigy100 points

    Hi Elad,

    Thank you.

    So: What is the best way for me to contact you directly?

    Should I use the contact form on your company's website? 

    Report Abuse
    • Reply
    You have posted to a forum that requires a moderator to approve posts before they are publicly available.
12
TI E2E™ Community
  • Support Forums
  • Blogs
  • Videos
  • Groups
  • Site Support & Feedback
  • Settings
TI E2E™ Community Groups
  • TI University Program
  • Make the Switch
  • Microcontroller Projects
  • Motor Drive & Control
Other Communities
  • Deyisupport
  • Designsomething.org
  • beagleboard.org
  • TI on Element 14
  • TI on TechXchangeSM
Other Technical & Support Resources
  • WEBENCH® Design Center
  • Product Information Centers
  • Technical Documents
  • TI Design Network
  • TI Technical Articles
  • TI Training

All content and materials on this site are provided "as is". TI and its respective suppliers and providers of content make no representations about the suitability of these materials for any purpose and disclaim all warranties and conditions with regard to these materials, including but not limited to all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement of any third party intellectual property right. TI and its respective suppliers and providers of content make no representations about the suitability of these materials for any purpose and disclaim all warranties and conditions with respect to these materials. No license, either express or implied, by estoppel or otherwise, is granted by TI. Use of the information on this site may require a license from a third party, or a license from TI.

Content on this site may contain or be subject to specific guidelines or limitations on use. All postings and use of the content on this site are subject to the Terms of Use of the site; third parties using this content agree to abide by any limitations or guidelines and to comply with the Terms of Use of this site. TI, its suppliers and providers of content reserve the right to make corrections, deletions, modifications, enhancements, improvements and other changes to the content and materials, its products, programs and services at any time or to move or discontinue any content, products, programs, or services without notice.

Follow Us Texas Instruments on Facebook Texas Instruments on Twitter Texas Instruments on LinkedIn Texas Instruments on Google+
TI Worldwide | Contact Us | my.TI Login | Site Map | Corporate Citizenship | mobile m.ti.com (Mobile Version)

TI is a global semiconductor design and manufacturing company. Innovate with 100,000+ analog ICs and
embedded processors, along with software, tools and the industry’s largest sales/support staff.

© Copyright 1995-2013 Texas Instruments Incorporated. All rights reserved.
Trademarks | Privacy Policy | Terms of Use