# \[lab 10 poisoning and sniffing \] \[ driftnet \] warning: link-level (LINUX\_SLL) header is not supported

**URL:** <https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000>\
**Category:** Penetration Testing Professional\
**Tags:** red, lab\
**Created:** [August 23, 2021, 12:22pm UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000 "2021-08-23T12:22:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sailaplam2-9d59ca5db](https://avatars.discourse-cdn.com/v4/letter/s/a5b964/32.png) [@sailaplam2-9d59ca5db](https://legacy-community.ine.com/u/sailaplam2-9d59ca5db)\
**Post date:** [August 23, 2021, 12:22pm UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/1 "2021-08-23T12:22:51Z")

</div>

Hello everyone, I was working on the lab 10 and have difficulties on getting driftnet to work. When I use command (with arpspoofing),

**driftnet -i tap0**

I get no images. When I use the command,

**driftnet**

It pops up the warning message “warning: link-level (LINUX\_SLL) header is not supported”. Can anyone help me to troubleshoot the driftnet? Thank you very much.

---

<div class="post-metadata">

**Author:** ![sailaplam2-9d59ca5db](https://avatars.discourse-cdn.com/v4/letter/s/a5b964/32.png) [@sailaplam2-9d59ca5db](https://legacy-community.ine.com/u/sailaplam2-9d59ca5db)\
**Post date:** [August 24, 2021, 2:57am UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/2 "2021-08-24T02:57:32Z")

</div>

update: I can capture pictures using eth0. When I use tap0 and arpspoofing, i can see the new connections in driftnet (wtih verbose on). However, I still cannot get the pictures.

---

<div class="post-metadata">

**Author:** ![okvitka-06ad02201ec2](https://avatars.discourse-cdn.com/v4/letter/o/ea666f/32.png) [@okvitka-06ad02201ec2](https://legacy-community.ine.com/u/okvitka-06ad02201ec2)\
**Post date:** [October 13, 2021, 7:37pm UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/3 "2021-10-13T19:37:56Z")

</div>

I see only black screen (driftnet), and no http traffic between 10.10.10.10 and 172.16.5.5 in Wireshark.  
I enabled ip forward and run two arpspoof commands. I used tap0, it’s my vpn interface.  
I can’t solve this issue… don’t understand why it doesn’t work…

---

<div class="post-metadata">

**Author:** ![friedrich\_o-93cd2df1](https://avatars.discourse-cdn.com/v4/letter/f/f14d63/32.png) [@friedrich\_o-93cd2df1](https://legacy-community.ine.com/u/friedrich_o-93cd2df1)\
**Post date:** [October 14, 2021, 6:26am UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/4 "2021-10-14T06:26:43Z")

</div>

> [@sailaplam2-9d59ca5db](#):
>
> I can capture pictures using eth0

that should not be the case - at least not for the lab pictures?

Could you provide the commands you executed?  
could you provide the out put of the following commands?  
`ip r`  
`ip a`  
`sysctl net.ipv4.ip_forward`  
`sudo iptables -L -n`  
`sudo iptables -L -n -tnat`

---

<div class="post-metadata">

**Author:** ![X0RW3LL](https://sea1.discourse-cdn.com/flex015/user_avatar/legacy-community.ine.com/x0rw3ll/32/190_2.png) [@X0RW3LL](https://legacy-community.ine.com/u/X0RW3LL)\
**Post date:** [October 14, 2021, 10:27am UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/5 "2021-10-14T10:27:31Z")

</div>

What Friedrich said—this is likely a misconfig somewhere.

The commands provided do the following (in case you’re unsure what they do):

```auto
ip r: shows routes
ip a: shows network interfaces (you can redact MAC addresses from this output)
sysctl net.ipv4.ip_forward: shows whether or not IPv4 packet forwarding is enabled
sudo iptables -L -n -tnat: lists iptables configs, numeric (no resolution), and NAT configs)

```

Also, an alternative to driftnet would be exporting objects from Wireshark.

---

<div class="post-metadata">

**Author:** ![jip.de.beer-717fecdd](https://avatars.discourse-cdn.com/v4/letter/j/ac91a4/32.png) [@jip.de.beer-717fecdd](https://legacy-community.ine.com/u/jip.de.beer-717fecdd)\
**Post date:** [November 11, 2021, 3:35pm UTC](https://legacy-community.ine.com/t/lab-10-poisoning-and-sniffing-driftnet-warning-link-level-linux-sll-header-is-not-supported/1000/6 "2021-11-11T15:35:01Z")

</div>

Could the issue be due to iptables? I had the same issue (no pictures in driftnet and didn’t see any HTTP traffic between the hosts) when `sudo iptables -L` showed `Chain FORWARD (policy DROP)`. After running `sudo iptables -P FORWARD ACCEPT` it started working for me. Got [the solution](https://legacy-community.ine.com/t/arp-poisoning-lab/651/12) thanks to @Z3r0n37.
