Can Sniffer running promiscuously detect ack packets

Started by Jasonhector, February 27, 2015, 04:31:42 AM

Jasonhector

Hi,
As the subject suggest, I wrote a sniffer that sniffs packets on the network running in promiscuous mode.
I looked inside the RF69 lib and dont see any methods regarding whether received data is a ack msg.

Are ack messages empty? What code would detect ack packets.

I have this method but it doesnt do anything [tried SENDERID as well]:

if(radio.ACKReceived(radio.TARGETID)){dbgF(" -ACKed by ");dbgH(radio.TARGETID,DEC);}


My sniffed packets look like this:
{ms since last msg}
[address]
(mqtt msg type)

00:45:59 {699}	[2]->[1] (CONNECT) 	B:4:20:1:0:5:6D:6F:74:65:32
00:45:59 {45}	[1]->[2] (CONNECT) 	
00:45:59 {38}	[1]->[2] (CONNACK) 	3:5:0
00:45:59 {30}	[2]->[1] (CONNACK) 	
00:45:59 {109}	[2]->[1] (REGISTER) 	E:A:0:0:0:1:32:2F:31:2F:40:49:2F:31
00:45:59 {56}	[1]->[2] (REGISTER) 	
00:45:59 {46}	[1]->[2] (REGACK) 	7:B:0:1:0:1:0
00:45:59 {42}	[1]->[2] (REGACK) 	7:B:0:1:0:1:0
00:45:59 {47}	[2]->[1] (REGISTER) 	F:A:0:0:0:2:32:2F:31:2F:40:41:2F:35:31
00:45:59 {89}	[2]->[1] (REGISTER) 	F:A:0:0:0:2:32:2F:31:2F:40:41:2F:35:31
00:45:59 {61}	[1]->[2] (REGACK) 	7:B:0:2:0:2:0
00:45:59 {42}	[1]->[2] (REGACK) 	7:B:0:2:0:2:0
00:45:59 {46}	[2]->[1] (REGISTER) 	F:A:0:0:0:3:32:2F:31:2F:40:41:2F:35:32
00:45:59 {89}	[2]->[1] (REGISTER) 	F:A:0:0:0:3:32:2F:31:2F:40:41:2F:35:32
00:46:00 {63}	[1]->[2] (REGACK) 	7:B:0:3:0:3:0
00:46:00 {42}	[1]->[2] (REGACK) 	7:B:0:3:0:3:0
00:46:00 {41}	[2]->[1] (REGACK) 	
00:46:00 {109}	[2]->[1] (SUBSCRIBE) 	F:12:0:0:4:31:2F:32:2F:24:4C:2F:31:30:31
00:46:00 {59}	[1]->[2] (SUBSCRIBE) 	
00:46:00 {48}	[1]->[2] (SUBACK) 	8:13:80:0:4:0:4:0
00:46:00 {41}	[1]->[2] (SUBACK) 	8:13:80:0:4:0:4:0
00:46:00 {47}	[2]->[1] (SUBSCRIBE) 	F:12:0:0:5:31:2F:32:2F:24:50:2F:31:35:31
00:46:00 {90}	[2]->[1] (SUBSCRIBE) 	F:12:0:0:5:31:2F:32:2F:24:50:2F:31:35:31
00:46:00 {66}	[1]->[2] (SUBACK) 	8:13:80:0:5:0:5:0
00:46:00 {41}	[1]->[2] (SUBACK) 	8:13:80:0:5:0:5:0
00:46:00 {42}	[2]->[1] (SUBACK) 	
00:46:00 {119}	[2]->[1] (PUBLISH) 	8:C:0:0:1:0:6:31
00:46:00 {41}	[2]->[1] (PUBLISH) 	8:C:0:0:1:0:6:31
00:46:00 {67}	[2]->[1] (PUBLISH) 	B:C:0:0:2:0:7:31:30:32:33
00:46:00 {49}	[1]->[2] (PUBLISH) 	
00:46:01 {128}	[2]->[1] (PUBLISH) 	A:C:0:0:3:0:8:38:35:30
00:46:01 {46}	[1]->[2] (PUBLISH) 	
00:46:01 {565}	[2]->[1] (PUBLISH) 	A:C:0:0:3:0:9:32:33:39
00:46:01 {46}	[1]->[2] (PUBLISH) 	
00:46:08 {6356}	[2]->[1] (PUBLISH) 	A:C:0:0:3:0:A:32:34:31
00:46:08 {46}	[1]->[2] (PUBLISH) 	
00:46:27 {19343}	[2]->[1] (PINGREQ) 	7:16:6D:6F:74:65:32
00:46:27 {39}	[1]->[2] (PINGREQ) 	
00:46:27 {34}	[1]->[2] (PINGRESP) 	2:17
00:46:27 {41}	[1]->[2] (PINGRESP) 	2:17
00:46:27 {42}	[1]->[2] (PINGRESP) 	2:17
00:46:27 {107}	[2]->[1] (PINGRESP) 	
00:46:29 {1330}	[2]->[1] (PUBLISH) 	A:C:0:0:3:0:B:32:34:33
00:46:29 {46}	[1]->[2] (PUBLISH) 	
00:46:35 {6793}	[2]->[1] (PUBLISH) 	A:C:0:0:2:0:C:38:39:30



Felix

ACK packets can be empty and usually are but you can send a data packet and mark it as ACK. Look at the header definition, there is 1 bit that is set if a packet is ACK and one if a packet requests ACK. The ACK bit is checked in the interrupt function.

TomWS

Quote from: Jasonhector on February 27, 2015, 04:31:42 AM
Hi,
As the subject suggest, I wrote a sniffer that sniffs packets on the network running in promiscuous mode.
I looked inside the RF69 lib and dont see any methods regarding whether received data is a ack msg.

Are ack messages empty? What code would detect ack packets.

I have this method but it doesnt do anything [tried SENDERID as well]:

if(radio.ACKReceived(radio.TARGETID)){dbgF(" -ACKed by ");dbgH(radio.TARGETID,DEC);}


<snip...>
Try:
if (radio.ACKReceived(RF69_BROADCAST_ADDR))...

This should match on any senderid

Tom

Jasonhector

Hi,
Thanks for this. I see that radio.ACK_RECEIVED also works. I somehow overlooked this.

TomWS

Quote from: Jasonhector on February 27, 2015, 09:43:01 AM
Hi,
Thanks for this. I see that radio.ACK_RECEIVED also works. I somehow overlooked this.
I was going to argue that the behavior is different between the two, and it is, but after thinking about it, for a sniffer, the flag is actually the better thing to use.

The reason is that a sniffer has to explicitly call receiveDone for every packet, including the Acks.   The radio.AckReceived() method does an 'extra' call to receiveDone() and therefore you could miss 'real' packets if they aren't Acks.  So, if, in your sniffer, you call receiveDone and, in addition to checking for content, you check the ACK_RECEIVED flag, you will see ALL cases.  The opposite is not true.

Tom
PS: I need to rework my 'snooper' now  :D