fast & selective & active scanning

Jouni Malinen jkmaline
Thu Feb 10 21:38:29 PST 2005

On Thu, Feb 10, 2005 at 09:12:30PM +0100, Angelo . wrote:

> Analyzing kismet and ethereal results, i see that probe request/response 
> happen in less than 1 ms. when card is scanning, it sends a broadcast probe 
> request and evidently waits for responses with a fixed timeout. i would be 
> able to modify dinamically this timeout or to interrupt scanning a channel, 
> i.e. when a probe request is received, but i fear that this code can be 
> handled only by the firmware...

Yes, this is done in firmware. If you want to do this yourself, you
would be better off using a card that has scanning implemented in the
driver (e.g., madwifi).

> is it possible to forge probe requests in a channel, and handle responses, 
> without loosing actual ap association in another channel?

HostScan should do this.

Jouni Malinen                                            PGP id EFC895FA

