
  -i, --ivs


    airodump-ng wls35u1 -i -w captures

    airodump-ng wls35u1 --i --write captures

  -g, --gpsd


    airodump-ng wls35u1 --gpsd

  -w <prefix>, --write <prefix>

    将捕获的包写入文件,默认有四种格式 .cap, .csv, .kismet.csv, .kistmet.netxml。保存的默认路径是当前路径,prefix为文件前缀。

    airodump-ng wls35u1 -w /home/captures

    airodump-ng wls35u1 --write /home/captures

  -e, --beacons


  -u <secs>, --update <secs>


    airodump-ng wls35u1 -u 2

    airodump-ng wls35u1 --update 2





  --berlin <secs>


    airodump-ng wls35u1 --berlin 15

  -c <channel>[,<channel>[,...]], --channel <channel>[,<channel>[,...]]


    airodump-ng wls35u1 -c 3

    airodump-ng wls35u1 -c 3,2,4-5,7-11

  -b <abg>, --band <abg>



      36, 40, 44, 48, 52, 56, 60, 64, 100, 104, 108,

      112, 116, 120, 124, 128, 132, 136, 140, 149,

      153, 157, 161, 184, 188, 192, 196, 200, 204,

      208, 212, 216,0


      1, 7, 13, 2, 8, 3, 14, 9, 4, 10, 5, 11, 6, 12, 0


      1, 7, 13, 2, 8, 3, 14, 9, 4, 10, 5, 11, 6, 12,

      36, 40, 44, 48, 52, 56, 60, 64, 100, 104, 108,

      112, 116, 120, 124, 128, 132, 136, 140, 149,

      153, 157, 161, 184, 188, 192, 196, 200, 204,

      208, 212, 216,0

    airodump-ng wls35u1 -b abg

    airodump-ng wls35u1 --band abg

  -s <method>, --cswitch <method>


      0 (FIFO, default value)

      1 (Round Robin)

      2 (Hop on last)

    airodump-ng wls35u1,wls35u2 -s 0

    airodump-ng wls35u1,wls35u2 --cswitch 0

  -r <file>


    airodump-ng wls35u1 -r captures.cap

  -x <msecs>

    Active Scanning Simulation (send probe requests and parse the

    probe responses).


      -M, --manufacturer

        airodump-ng wls35u1 -M

        airodump-ng wls35u1 --manufacturer

      -U, --uptime


        airodump-ng wls35u1 -U

        airodump-ng wls35u1 --uptime

  -W, --wps


    airodump-ng wls35u1 -W

    airodump-ng wls35u1 --wps

  --output-format <formats>

    输出文件类型: pcap, ivs, csv, gps, kismet, netxml。默认的类型为: pcap, csv, kismet, kismet-newcore.需与-w或--write配合使用

    airodump-ng wls35u1 -w capture --output-format 'csv'

  -I <seconds>, --write-interval <seconds>



    移除右上角显示的信息'fixed channel <interface>: -1'

  -f <msecs>


    airodump-ng wls35u1 -f 2000

  -C <frequencies>


    airodump-ng wls35u1 -C 2412-2472,5180-5825


  -t <OPN|WEP|WPA|WPA1|WPA2>, --encrypt <OPN|WEP|WPA|WPA1|WPA2>

    捕获特定加密方式的数据: '-t OPN -t WPA2'

    airodump-ng wls35u1 -t WPA2

    airodump-ng wls35u1 --encrypt WPA2

  -d <bssid>, --bssid <bssid>

    捕获规定bssid(ap mac)的数据

    airodump-ng wls35u1 -d 88:25:93:C1:C2:FC

    airodump-ng wls35u1 --bssid 88:25:93:C1:C2:FC

  -m <mask>, --netmask <mask>


    airodump-ng wls35u1 -d 88:25:93:C1:C2:FC -m FF:FF:FF:00:00:00

    airodump-ng wls35u1 --bssid 88:25:93:C1:C2:FC --netmask FF:FF:FF:00:00:00


    不显示 (not associated) 标识的终端信息

    airodump-ng wls35u1 -a

  -N, --essid

    捕获规定的essid(ap name)的数据

    airodump-ng wls35u1 -N google

    airodump-ng wls35u1 --essid google

  -R, --essid-regex

    Filter APs by ESSID using a regular expression.


airodump-ng can receive and interpret key strokes while running. The

following list describes the currently assigned keys and supposed


a Select active areas by cycling through these display options:

AP+STA; AP+STA+ACK; AP only; STA only

d Reset sorting to defaults (Power)

i Invert sorting algorithm

m Mark the selected AP or cycle through different colors if the

selected AP is already marked

r (De-)Activate realtime sorting - applies sorting algorithm

everytime the display will be redrawn

s Change column to sort by, which currently includes: First seen;

BSSID; PWR level; Beacons; Data packets; Packet rate; Channel;

Max. data rate; Encryption; Strongest Ciphersuite; Strongest

Authentication; ESSID

SPACE Pause display redrawing/ Resume redrawing

TAB Enable/Disable scrolling through AP list

UP Select the AP prior to the currently marked AP in the displayed

list if available

DOWN Select the AP after the currently marked AP if available

If an AP is selected or marked, all the connected stations will also be

selected or marked with the same color as the corresponding Access



airodump-ng -c 9 wlan0mon

Here is an example screenshot:


CH 9 ][ Elapsed: 1 min ][ 2007-04-26 17:41 ][ BAT: 2 hours 10 mins ][

WPA handshake: 00:14:6C:7E:40:80



00:09:5B:1C:AA:1D 11 16 10 0 0 11 54. OPN

<length: 7>

00:14:6C:7A:41:81 34 100 57 14 1 9 11 WEP WEP


00:14:6C:7E:40:80 32 100 752 73 2 9 54 WPA TKIP

PSK teddy



00:14:6C:7A:41:81 00:0F:B5:32:31:31 51 11-11 2 14 big‐


(not associated) 00:14:A4:3F:8D:13 19 11-11 0 4 mossy

00:14:6C:7A:41:81 00:0C:41:52:D1:D1 -1 11-2 0 5 big‐


00:14:6C:7E:40:80 00:0F:B5:FD:FB:C2 35 36-24 0 99 teddy


BSSID MAC address of the access point. In the Client section, a BSSID

of "(not associated)" means that the client is not associated

with any AP. In this unassociated state, it is searching for an

AP to connect with.

PWR Signal level reported by the card. Its signification depends on

the driver, but as the signal gets higher you get closer to the

AP or the station. If the BSSID PWR is -1, then the driver

doesn't support signal level reporting. If the PWR is -1 for a

limited number of stations then this is for a packet which came

from the AP to the client but the client transmissions are out

of range for your card. Meaning you are hearing only 1/2 of the

communication. If all clients have PWR as -1 then the driver

doesn't support signal level reporting.

RXQ Only shown when on a fixed channel. Receive Quality as measured

by the percentage of packets (management and data frames) suc‐

cessfully received over the last 10 seconds. It's measured over

all management and data frames. That's the clue, this allows you

to read more things out of this value. Lets say you got 100 per‐

cent RXQ and all 10 (or whatever the rate) beacons per second

coming in. Now all of a sudden the RXQ drops below 90, but you

still capture all sent beacons. Thus you know that the AP is

sending frames to a client but you can't hear the client nor the

AP sending to the client (need to get closer). Another thing

would be, that you got a 11MB card to monitor and capture frames

(say a prism2.5) and you have a very good position to the AP.

The AP is set to 54MBit and then again the RXQ drops, so you

know that there is at least one 54MBit client connected to the



Number of beacons sent by the AP. Each access point sends about

ten beacons per second at the lowest rate (1M), so they can usu‐

ally be picked up from very far.

#Data Number of captured data packets (if WEP, unique IV count),

including data broadcast packets.

#/s Number of data packets per second measure over the last 10 sec‐


CH Channel number (taken from beacon packets). Note: sometimes

packets from other channels are captured even if airodump-ng is

not hopping, because of radio interference.

MB Maximum speed supported by the AP. If MB = 11, it's 802.11b, if

MB = 22 it's 802.11b+ and higher rates are 802.11g. The dot

(after 54 above) indicates short preamble is supported. 'e'

indicates that the network has QoS (802.11e) enabled.

ENC Encryption algorithm in use. OPN = no encryption,"WEP?" = WEP or

higher (not enough data to choose between WEP and WPA/WPA2), WEP

(without the question mark) indicates static or dynamic WEP, and

WPA or WPA2 if TKIP or CCMP or MGT is present.

CIPHER The cipher detected. One of CCMP, WRAP, TKIP, WEP, WEP40, or

WEP104. Not mandatory, but TKIP is typically used with WPA and

CCMP is typically used with WPA2. WEP40 is displayed when the

key index is greater then 0. The standard states that the index

can be 0-3 for 40bit and should be 0 for 104 bit.

AUTH The authentication protocol used. One of MGT (WPA/WPA2 using a

separate authentication server), SKA (shared key for WEP), PSK

(pre-shared key for WPA/WPA2), or OPN (open for WEP).

WPS This is only displayed when --wps (or -W) is specified. If the

AP supports WPS, the first field of the column indicates version

supported. The second field indicates WPS config methods (can be

more than one method, separated by comma): USB = USB method,

ETHER = Ethernet, LAB = Label, DISP = Display, EXTNFC = External

NFC, INTNFC = Internal NFC, NFCINTF = NFC Interface, PBC = Push

Button, KPAD = Keypad. Locked is displayed when AP setup is


ESSID The so-called "SSID", which can be empty if SSID hiding is acti‐

vated. In this case, airodump-ng will try to recover the SSID

from probe responses and association requests.


MAC address of each associated station or stations searching for

an AP to connect with. Clients not currently associated with an

AP have a BSSID of "(not associated)".

Rate This is only displayed when using a single channel. The first

number is the last data rate from the AP (BSSID) to the Client

(STATION). The second number is the last data rate from Client

(STATION) to the AP (BSSID).

Lost It means lost packets coming from the client. To determine the

number of packets lost, there is a sequence field on every non-

control frame, so you can subtract the second last sequence num‐

ber from the last sequence number and you know how many packets

you have lost.


The number of data packets sent by the client.

Probes The ESSIDs probed by the client. These are the networks the

client is trying to connect to if it is not currently connected.

The first part is the detected access points. The second part is a list

of detected wireless clients, stations. By relying on the signal power,

one can even physically pinpoint the location of a given station.


  1. Linux使用手册-vi使用手册

    vi使用手册 VI是unix上最常用的文本编辑工具,作为unix软件测试人员,有必要熟练掌握它. 进入vi的命令 vi filename :打开或新建文件,并将光标置于第一行首 vi +n filen ...

  2. WHM使用手册by lin

    WebHost Manager 11使用手册(WHM使用手册) 本手册翻译自cpanel官方文档. 本翻译中文版本版权归美国主机侦探所有,未经允许,禁止复制. Overview(概述) 本用户手册主要 ...

  3. Linux帮助手册(man)

    Linux的帮助文档 在我们使用Linux的过程中,都会遇到这样那样的问题,一般我们在计算机能连上网的情况下会进行百度或Google解决问题,但是并不是所有文题都能在网上很快得到答案.万一我们是在没有 ...

  4. Spring Security 5.0.x 参考手册 【翻译自官方GIT-2018.06.12】

    源码请移步至:https://github.com/aquariuspj/spring-security/tree/translator/docs/manual/src/docs/asciidoc 版 ...

  5. hydra-microservice 中文手册(3W字预警)

    Hydras 是什么? Hydra 是一个 NodeJS 包(技术栈不是重点,思想!思想!思想!),它有助于构建分布式应用程序,比如微服务. Hydra 提供服务发现(service discover ...

  6. FREERTOS 手册阅读笔记

    郑重声明,版权所有! 转载需说明. FREERTOS堆栈大小的单位是word,不是byte. 根据处理器架构优化系统的任务优先级不能超过32,If the architecture optimized ...

  7. JS魔法堂:不完全国际化&本地化手册 之 理論篇

    前言  最近加入到新项目组负责前端技术预研和选型,其中涉及到一个熟悉又陌生的需求--国际化&本地化.熟悉的是之前的项目也玩过,陌生的是之前的实现仅仅停留在"有"的阶段而已. ...

  8. 转职成为TypeScript程序员的参考手册

    写在前面 作者并没有任何可以作为背书的履历来证明自己写作这份手册的分量. 其内容大都来自于TypeScript官方资料或者搜索引擎获得,期间掺杂少量作者的私见,并会标明. 大部分内容来自于http:/ ...

  9. Redis学习手册(目录)

    为什么自己当初要选择Redis作为数据存储解决方案中的一员呢?现在能想到的原因主要有三.其一,Redis不仅性能高效,而且完全免费.其二,是基于C/C++开发的服务器,这里应该有一定的感情因素吧.最后 ...

  10. JS魔法堂:不完全国际化&本地化手册 之 实战篇

    前言  最近加入到新项目组负责前端技术预研和选型,其中涉及到一个熟悉又陌生的需求--国际化&本地化.熟悉的是之前的项目也玩过,陌生的是之前的实现仅仅停留在"有"的阶段而已. ...


  1. 为什么说程序员都应该玩一玩GitHub

    既熟悉又陌生的GitHub 关于GitHub,相信每一个程序员都再熟悉不过了.它为开发者提供Git仓库的托管服务,是全世界最大的代码集中地,被戏称为“全球最大同性交友网站”. 但是对于很大一部分程序员 ...

  2. PHP连接SQL Server数据库

    服务环境:apache2.2 + PHP5.2 + Sql Server 2008 R2 一.所需库和工具1.SQLSRV20.EXE (php5.2版本对应的的Sql Server扩展库)注释:ph ...

  3. [#1] YCbCr与RGB的转换公式

    1 YCbCr简介 YCbCr颜色空间是将RGB颜色空间进行坐标转换后得到的,常用于数字电视系统.Y取值范围:16~235 Cb.Cr的取值范围:16~240 YCbCr经常和YUV混淆.两者的主要差 ...

  4. 当谈到 GitLab CI 的时候,我们该聊些什么(上篇)

    "微服务"这个概念近两年非常热,正在慢慢改变 DevOps 的思路.微服务架构把一个庞大的业务系统拆解开来,每一个组件变得更加独立自治.松耦合.但是,同时也伴随着部署单元粒度越来越 ...

  5. JS代码中!!的用法,以及代码性能对比

    一.!!的理解 解释: !!的意思就是把一个任意类型的值转换为布尔类型的值,一个!是取非 再一个!又取非,相当于把这个数据转换为boolen类型了. 使用场景: 常常用在if(a).if(!!a)这样 ...

  6. C# 动态加载卸载 DLL

    我最近做的软件,需要检测dll或exe是否混淆,需要反射获得类名,这时发现,C#可以加载DLL,但不能卸载DLL.于是在网上找到一个方法,可以动态加载DLL,不使用时可以卸载. 我在写一个WPF 程序 ...

  7. 初学python之,IDLE安装

    首先新手上路,写的第一篇博客,希望大家不要吐槽. 1.首先在python官网下载最新python版本 https://www.python.org/(注意根据自己的操作系统来选版本) 安装很简单傻瓜式 ...

  8. 大话JPA

    JPA 是什么 Java Persistence API:用于对象持久化的 API Java EE 5.0 平台标准的 ORM 规范,使得应用程序以统一的方式访问持久层: 首先看一下传统方式访问数据库 ...

  9. Ajax.Nodejs.跨域访问

    使用环境: 客户端: jQuery 服务器: Node.js 在通过Ajax调用非本域的链接/接口时, 一般是不能成功的, 就算是同一个IP下不同的端口也被认作跨域访问 解决办法记录如下: 客户端: ...

  10. LeetCode 381. Insert Delete GetRandom O(1) - Duplicates allowed (插入删除和获得随机数 常数时间 允许重复项)

    Design a data structure that supports all following operations in average O(1) time. Note: Duplicate ...