PDA

View Full Version : [FRESH NEWZ] Aircrack-ng 1.0 Devel


shamanvirtuel
06-27-2007, 09:08 AM
some fresh newz of devel version....i will update this thread......according to 1.0 reliz enhancements

Current Build : 1.0 Dev r501
06/27/2K7

Fixed :
FIX : Passive ptw attack fixed
FIX : sensitivity report for rtl8187(patch v4 now included).
FIX : Aireplay-ng --test 100% cpu usage bug fixed

Current Build : 1.0 Dev r507
06/27/2K7

Fixed :
FIX : Another bitrate fix for madwifi-ng. (using iwconfig instead of ioctl)
FIX : Wrong information printed in CSV file (PSK for WEP with Shared key instead of SKA)

Added :
ADD : dynamic maximum per packet time (depending on airserv-ng) to --test
ADD : pwr value and missing bitrates to --test

Current Build : 1.0 Dev r508

Timestamp:06/28/07 16:40:50 (1 hour ago)
Author:hirte
Fixed :
FIX :Fixed airodump monitor mode usage on orinoco_cs (no wext monitor mode support).
FIX :Fixed bitrate error handling.

Current Build : 1.0 Dev r509
Timestamp:06/29/07 00:27:27 (12 hours ago)

Author:hirte

Added :

ADD : Added multiple keystreams per IV to the new IVS format (allowing ptw on ip packets using --ivs now).

Current Build : 1.0 Dev r516


[516] (http://trac.aircrack-ng.org/changeset/516) by hirte on 07/02/07 01:27:37
Fixed aircrack-ng's huge memory usage when using -z with hundreds of APs.

[515] (http://trac.aircrack-ng.org/changeset/515) by hirte on 07/02/07 01:25:51
Fixed new ivs2 file header usage.

[514] (http://trac.aircrack-ng.org/changeset/514) by hirte on 07/01/07 18:20:38
Atheros bitrate fix.

[513] (http://trac.aircrack-ng.org/changeset/513) by misterx on 07/01/07 15:17:51
Added categories (replay options specific to an attack) to replay options.

[512] (http://trac.aircrack-ng.org/changeset/512) by hirte on 07/01/07 15:16:10
Added version tag to new ivs format. Added multiple packets and new ivs format support to packetforge-ng.

[511] (http://trac.aircrack-ng.org/changeset/511) by gandalf on 06/29/07 23:11:15
manpages: "-" must be escaped otherwise groff interprets them as hyphens.

Current Build : 1.0 Dev r521

ULTRA USEFUL REVISIONS......

revisions really cool today..............

521 really ****ing cool !!!!!
517 a really good evolution too....

[521] (http://trac.aircrack-ng.org/changeset/521) by hirte on 07/02/07 16:55:08
aireplay-ng: Added --fast switch to choose first matching packet for -2,-4 and -5 and to quit -9 once injection is working. Added --bitrate switch to enable bitrate testing in --test, deactivated by default.

[520] (http://trac.aircrack-ng.org/changeset/520) by hirte on 07/02/07 15:26:50
Fixed typo. :/

[519] (http://trac.aircrack-ng.org/changeset/519) by hirte on 07/02/07 12:20:16
Added kill info to process detection

[518] (http://trac.aircrack-ng.org/changeset/518) by hirte on 07/02/07 12:05:04
Added network manager detection to airmon-ng.

[517] (http://trac.aircrack-ng.org/changeset/517) by hirte on 07/02/07 10:00:01
Added a second ptw session. It will now try two ptw attacks, first using only the "arp" keystreams (if there are 99+ arp ivs) and in a second run (if key wasn't found yet) using all available keystreams, including ip packets.

Current Build : 1.0 Dev r523 (http://trac.aircrack-ng.org/changeset/523) so......now we can crack 256 bit key with aircrack ptw attack.......now airdriver download the latest patches

[523] (http://trac.aircrack-ng.org/changeset/523) by hirte on 07/04/07 00:10:58
airdriver-ng patch update.
[522] (http://trac.aircrack-ng.org/changeset/522) by hirte on 07/03/07 15:58:22
makeivs 256bit support.

we are 529
Current Build : 1.0 Dev r529
07/05/2K7
[529] (http://trac.aircrack-ng.org/changeset/529) by hirte on 07/05/07 02:20:15
airdriver-ng: Fixed iteration for device detections.
[528] (http://trac.aircrack-ng.org/changeset/528) by hirte on 07/05/07 02:08:44
airmon-ng: Fixed per interface process detection.
[527] (http://trac.aircrack-ng.org/changeset/527) by hirte on 07/05/07 02:05:48
airdriver-ng: Added ndiswrapper, ipwraw and better detection.
[526] (http://trac.aircrack-ng.org/changeset/526) by hirte on 07/05/07 02:04:48
airmon-ng: Nicer process detection output.
[525] (http://trac.aircrack-ng.org/changeset/525) by misterx on 07/04/07 22:55:01
Fix a future compiling issue we may get.
[524] (http://trac.aircrack-ng.org/changeset/524) by hirte on 07/04/07 22:30:34
nicer pcap.h

Current Build 532

[532] (http://trac.aircrack-ng.org/changeset/532) by hirte on 07/05/07 16:31:42
airdriver-ng: fixed function calls
[531] (http://trac.aircrack-ng.org/changeset/531) by hirte on 07/05/07 16:25:23
airdriver-ng: fixed supported list
[530] (http://trac.aircrack-ng.org/changeset/530) by hirte on 07/05/07 16:20:07
airdriver-ng: Added svn, git and stack_detection support.


[546] (http://trac.aircrack-ng.org/changeset/546) by hirte on 07/09/07 01:09:22
Added rt2500 and rt61 detection to airdriver-ng. (thanks to a-slack).
[545] (http://trac.aircrack-ng.org/changeset/545) by hirte on 07/09/07 00:53:35
Added patch for keyspace restriction using ptw attack. (by erik tews)
[544] (http://trac.aircrack-ng.org/changeset/544) by hirte on 07/08/07 23:36:52
patchchk: fixed absolute path to patchfile usage
[543] (http://trac.aircrack-ng.org/changeset/543) by misterx on 07/08/07 17:54:01
Fixed detection of N770 wireless interface (Closes: #263 (http://trac.aircrack-ng.org/ticket/263))
[542] (http://trac.aircrack-ng.org/changeset/542) by hirte on 07/08/07 13:38:21
added patchchk: small script; trying to find correct path and arguments to successfully apply a given patch.
[541] (http://trac.aircrack-ng.org/changeset/541) by hirte on 07/07/07 20:29:02
Fixed an airdriver-ng issue with "tar".

15:35 Changeset [540] by misterx (http://trac.aircrack-ng.org/changeset/540) Added requirements to compile this version.
15:19 Ticket #262 (enhancement) created by darkAudax (http://trac.aircrack-ng.org/ticket/262)configure script for airolib-ng10:49 Changeset [539] by sorbo (http://trac.aircrack-ng.org/changeset/539) compile airolib
10:27 Changeset [538] by hirte (http://trac.aircrack-ng.org/changeset/538) Added airolib-ng.c
08:54 Changeset [537] by sorbo (http://trac.aircrack-ng.org/changeset/537) fix warning
02:42 Ticket #261 (defect) created by anonymous (http://trac.aircrack-ng.org/ticket/261)chopchop bssid filter does not work00:28 Changeset [536] by sorbo (http://trac.aircrack-ng.org/changeset/536) got rid of some warning. commented out airolib - commit airolib-ng.c
22:05 Changeset [535] by misterx (http://trac.aircrack-ng.org/changeset/535) airdecap-ng: Fixed bug in calc_pmk() function that causes wrong PMK to be computed (Closes: #215 (http://trac.aircrack-ng.org/ticket/215))
23:57 Changeset [534] by hirte (http://trac.aircrack-ng.org/changeset/534) Added ebfes 'airolib' patches to allow hash table usage in aircrack-ng through sqlite. WARNING: 1.0-dev needs libsqlite-dev >= 3.3.17 as of now, or it won't compile.
22:06 Changeset [533] by hirte (http://trac.aircrack-ng.org/changeset/533) airdriver-ng: several fixes and sanity checks.
16:31 Changeset [532] by hirte (http://trac.aircrack-ng.org/changeset/532) airdriver-ng: fixed function calls

Current Build 546

-=Xploitz=-
06-27-2007, 02:09 PM
Cool..Ill check it out...literally. ;)

Thanks Niko!

shamanvirtuel
06-28-2007, 07:58 PM
Current Build : 1.0 Dev r508

Timestamp:06/28/07 16:40:50 (1 hour ago)
Author:hirte
Fixed :
FIX :Fixed airodump monitor mode usage on orinoco_cs (no wext monitor mode support).
FIX :Fixed bitrate error handling.

1 hour ago : FRESHZ newz -- Good Newz
;)

-=Xploitz=-
06-28-2007, 08:03 PM
Good God Shaman. Do they release a new revision on a daily basis or what? How many bugs could there possibly be left after all these years??

shamanvirtuel
06-28-2007, 08:11 PM
no they deliver these release as soon one person have finish to fix one bug...so yes there so many revision.......1.0 will be like a really evolution and a major reliz i think..........

so i will offer here all(if i don't miss some...some days there's 5 or 6 revisions) with their news...until 1.0 out


hope it could be useful

-=Xploitz=-
06-28-2007, 08:13 PM
Definitely useful Niko. Thanks for the updates.

-=Xploitz=-
06-29-2007, 05:46 PM
Current Build : 1.0 Dev r509
Timestamp:06/29/07 00:27:27 (12 hours ago)

Author:hirte

Added :

ADD : Added multiple keystreams per IV to the new IVS format (allowing ptw on ip packets using --ivs now).
.

So does this mean we can now do --ivs and use ptw ??? If soo..cool..saves me disk space!

theprez98
06-29-2007, 05:55 PM
So does this mean we can now do --ivs and use ptw ??? If soo..cool..saves me disk space!
Your mission is now to try it, find out, and report back.

-=Xploitz=-
06-29-2007, 07:27 PM
Your mission is now to try it, find out, and report back.

How dare you make me do my own work! What happened to "Spoonfeeder Extraordinaire"?? :p Guess I'm not special anymore huh? :( Oh well..

BTW..just in case you were serious...:rolleyes:

Mission successful...

Yes. The PTW attack does work with the --ivs option in airodump now Mr. Comedian.
Beam me up Scotty!

shamanvirtuel
06-30-2007, 03:34 AM
yes, it's why my new baby needs 1.0 dev and for wesside-ng too
.....

really cool even if ivs format will probably be replaced by a new file format..........

PrairieFire
07-05-2007, 02:08 AM
r534
WARNING: 1.0-dev needs libsqlite-dev >= 3.3.17 as of now, or it won't compile.


nothing is missing in source code but there's something wrong in the makefile.


http://sqlite.org/sqlite-3.4.0.tar.gz
BT2:
sqlite3 -version
3.3.7

Possible update procedure?
curl -O http://www.sqlite.org/sqlite-3.4.0.tar.gz
tar xvzf sqlite-3.4.0.tar.gz
cd sqlite-3.4.0
./configure --prefix=/usr/local
make && make install

PrairieFire
07-06-2007, 08:14 PM
Do not update reason above

balding_parrot
07-09-2007, 08:47 PM
r534
WARNING: 1.0-dev needs libsqlite-dev >= 3.3.17 as of now, or it won't compile.




http://sqlite.org/sqlite-3.4.0.tar.gz
BT2:
sqlite3 -version
3.3.7

Possible update procedure?
curl -O http://www.sqlite.org/sqlite-3.4.0.tar.gz
tar xvzf sqlite-3.4.0.tar.gz
cd sqlite-3.4.0
./configure --prefix=/usr/local
make && make install


Sorry to say, but this does not work.:(

I have found the solution and will be posting the fix and precompiled module a little later.
Just got to write the TUT and upload the file after just a tiny bit more testing:cool:

balding_parrot
07-09-2007, 10:13 PM
Just posted a fix for this here

http://forums.remote-exploit.org/showthread.php?t=7460

PrairieFire
07-13-2007, 08:02 PM
Nice addition:
r558 - Made ptw attack default. removed "-z", added "-K" for korek attack usage. Added "-M" to define maximum number of ivs to use.
Current revision: r560

-=Xploitz=-
07-14-2007, 12:20 AM
Seems theres another project for balding_parrot....

revision 564 by the way

bt 1.0-dev # make
....blah....everything goes well...then I get this at the end...

include -DHAVE_SQLITE -c -o buddy-ng.o buddy-ng.c
buddy-ng.c: In function `drop_privs':
buddy-ng.c:161: warning: implicit declaration of function `setgroups'
make[1]: *** [buddy-ng.o] Error 1
make[1]: Leaving directory `/root/1.0-dev/src'
make: *** [all] Error 2


btw this is with following your Instructions....


So the procedure to fix this is thus:

Code:
curl -O http://www.sqlite.org/sqlite-3.4.0.tar.gz
tar xvzf sqlite-3.4.0.tar.gz
cd sqlite-3.4.0
./configure --prefix=/usr/local
make
and at this point we need to edit the makefile

At the bottom of the original makefile you will find this:

Code:
$(INSTALL) -m 0644 sqlite3.pc $(DESTDIR)$(libdir)/pkgconfig;

tcl_install: libtclsqlite3.la
tclsh $(TOP)/tclinstaller.tcl $(VERSION)

clean:
rm -f *.lo *.la *.o sqlite3$(TEXE) libsqlite3.la
Which you need to edit to this:

Code:
$(INSTALL) -m 0644 sqlite3.pc $(DESTDIR)$(libdir)/pkgconfig;

tcl_install: libtclsqlite3.la
tclsh8.4 $(TOP)/tclinstaller.tcl $(VERSION)

clean:
rm -f *.lo *.la *.o sqlite3$(TEXE) libsqlite3.la
and thats it, you can continue as normal

Code:
make install
Your done, finished and now you can continue to use aircrack-ng 1.0 r540 or above.
.


Any thoughts why Im getting these errors at the end??:confused:

PrairieFire
07-14-2007, 12:36 AM
r565 - fix linux compile
update to 566.

btw anyone notice:

easside-ng <arg> [v0]
-h help
-v AP mac
-m my mac
-i my ip
-r rtr ip
-s buddy ip
-f interface

-=Xploitz=-
07-14-2007, 12:48 AM
eastside?? OMFG!!!

Its a gang war!!!! http://forum.playstadium.dk/images/smilies/068.gifEastside -VS- Westside! http://forum.playstadium.dk/images/smilies/firing.gif

PrairieFire
07-14-2007, 12:53 AM
well I got it working sort - of

Setting tap MTU
Sorting out wifi MAC
easside-ng: wi_set_mac(): Bad address

-=Xploitz=-
07-14-2007, 12:54 AM
yep..updated again to 566 and alls well.

balding_parrot
07-14-2007, 02:09 AM
So is it still broken or fixed ?

Just so as I know before firing up the other machine and start looking at it for no reason.

whats this easside ? not looked at aircrack for a couple of days, well not since that marathon 2 1/2 day session.

Just got back from taking son to harry potter so not quite with it at the moment.

PrairieFire
07-14-2007, 02:17 AM
Works fine,

it is a 0day addition no info has been wrote for it yet.

-=Xploitz=-
07-14-2007, 02:18 AM
Its fixed!! dunno about eastside yet..no documentation I could fing on the air crack-smokers site. Did I ever mention how much I loathe them??

shamanvirtuel
07-14-2007, 02:25 AM
easside-ng seems to be a convenient way to distribute a kind of wesside-ng other your lan(or through pcs)

i find it needs to create a tunnel interface(modprobe tun before) and need at last the server ip(called buddy ip -s)

the server is launched at the command line by
buddy-ng

will say waiting for connection

so now i think we need to launch easside on the remote computer
easside-ng -s ipofbuddy-ng -f interface

i unfortunatly can't test my though because got only one pc tonight
maybe tomorrow i can try

or if any manage to do something.........;pliz feedback.......

BTW thx 4 update because i don't have time with the reliz of beta2 of AIR to finish..........

PrairieFire
07-14-2007, 02:28 AM
My attempts so far with easside-ng
First try with DWL-G650:


wlanconfig ath0 destroy
macchanger --mac 00:11:22:33:44:55 wifi0
airmon-ng start wifi0
easside-ng -s 192.168.1.10 -v 00:18:85:1B:98:71 -m 00:11:22:33:44:55 -f ath0

Setting tap MTU
Sorting out wifi MAC
easside-ng: wi_set_mac(): Bad address

shamanvirtuel
07-14-2007, 02:30 AM
i think you need to start buddy-ng on the server computer before

PrairieFire
07-14-2007, 02:41 AM
Loading it up on my FON/aircrack build now will see if it will even communicate.

balding_parrot
07-14-2007, 02:47 AM
Its fixed!! dunno about eastside yet..no documentation I could fing on the air crack-smokers site. Did I ever mention how much I loathe them??

Cool... so it was them then :cool:

Will have to be patient then, and wait for some docs:(

So you don't like the nice people there then :rolleyes: or is it the other way round:rolleyes:
Hmmmmm..... I wonder why ??

-=Xploitz=-
07-14-2007, 03:22 AM
I'm sure the feeling is MUTUAL. And I know you know why..hell I got a thread here I hijacked from somebody and turned it into an aircrack- smoker rant..just yesterday..I think. ;) Sorry to the guy whose thread I hijacked BTW.

shamanvirtuel
08-11-2007, 10:58 PM
ok there's long time i don't updated the thread , im sorry for that , but i was coding so many project at the same time......time was missing...

here is a great update
new airodump-ng option

--berlin

/* 302 * The name for this option may look quite strange, here is the story behind it: 303 * During the CCC2007, 10 august 2007, we (hirte, Mister_X) went to visit Berlin 304 * and couldn't resist to turn on airodump-ng to see how much access point we can 305 * get during the trip from Finowfurt to Berlin. When we were in Berlin, the number 306 * of AP increase really fast, so fast that it couldn't fit in a screen, even rotated; 307 * the list was really huge (we have a picture of that). The 2 minutes timeout 308 * (if the last packet seen is higher than 2 minutes, the AP isn't shown anymore) 309 * wasn't enough, so we decided to create a new option to change that timeout. 310 * We implemented this option in the highest tower (TV Tower) of Berlin, eating an ice. 311 */



enjoy









i bet could be cool to test !!!
i will report

shamanvirtuel
08-11-2007, 11:17 PM
CH 7 ][ Elapsed: 20 s ][ 2007-08-12 00:19 ][ 1/ 1/ 0

BSSID PWR Beacons #Data, #/s CH MB ENC CIPHER AUTH ESSID

00:1A:6B:04:9E:2F 111 14 0 0 10 54 WEP WEP Livebox

BSSID STATION PWR Rate Lost Packets Probes


after test when hopping

airodump-ng rausb0 --berlin 1000

the 1000 is the new timeout delay before airodump-ng drop ap wich receive no packets from list
default is 120 seconds

[ 1/ 1/ 0

first is number of ap detected and visible in the current list
second is total ap found (even those wich are out of screen)
third will occur only if list fill screen , it will output the time it takes to fill in the screen with aps....

this mode will be useful for scripting ..... new infos available...
must work on it