WarDriving: Drive, Detect, Defend: A Guide to Wireless Security

Kismet is the most popular WarDriving application for Linux users. Unlike NetStumbler, Kismet is a passive wireless scanner. A passive scanner does not broadcast, it simply listens for any traffic on the 802.11 bands. To accomplish this, the wireless card must be put into monitor mode. Contrary to popular belief, monitor mode and promiscuous mode are not the same thing. Monitor mode allows the card to capture packets without associating with a specific network. Promiscuous mode allows the card to capture any packets transmitted on the network that the card is associated with. Kismet requires monitor mode because it can be configured to channel hop. Channel hopping is configuring the card to listen on a channel for a specified time frame and then change or hop to another channel. Channel hopping allows Kismet to discover wireless networks that are broadcasting on any of the 802.11 specified channel frequencies. Getting a card into monitor mode has generally been the stumbling block for new WarDrivers that want to use Kismet. Enabling monitor mode on many cards can be a frustrating, if not difficult, process. This chapter details the process of enabling monitor mode on two of the most common chipsets: Hermes and Prism 2.
In addition to its other features, Kismet doesn t rely on the Service Set Identifier (SSID) broadcast beacon to determine the existence of a wireless access point. Therefore, more access points can often be discovered. This is useful while WarDriving and when attempting to find rogue access points...