logo       

Re: Continous Preamble DoS?: msg#00001

security.wireless

Subject: Re: Continous Preamble DoS?

Yes,
check this http://www.auscert.org.au/render.html?it=4091

It exist because it's usefull for network problem debugging, initially
it exists as PLME.DSSSTESTMODE primitive in 802.11b standard and
because it's obvius potential damage it was removed from comercial
driver versions.

2007/5/2, Seth Fogie <seth-9/fkfX+J4VRfOZc0+OmrVg@xxxxxxxxxxxxxxxx>:
I recently came across this driver that allows the Linksys WCF54G card
to support wireless sniffing from WM5. Typical stuff...except then I
noticed something called ' Continuous preamble mode ', which I had never
heard before...

I asked the creator about it and this was his response:
Primary I needed WM5.0 driver for WCF54G card.
Driver was written with Linux similar driver sources information.
In these sources I found continuos preamble debug option.
I had only mode Name and Comments...

Possible GPL issues aside, when I enable this mode my network goes down.
However, no packets are detected using Airmagnet, Wireshark, or any
other program. AirPCap does pickup something...but it is like random data.

I used an RF analyzer to see if it was doing something odd and sure
enough, when I enabled the mode I saw a HUGE spike in RF around channel
6 (current channel) and then a constant RF emission from then on spread
across the entire 2.4 range.

Has anyone seen anything like this or know what it could be or why it
exists?

Thanks
Seth




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise