View Full Version : How, when there are no clients?
hongman
03-13-2006, 03:19 PM
Hi all
Ok, so now I'm ok with cracking most WEP wlans with clients.
My next step - learn how to do it if there are NO clients.
I know Aireplay can associate with the AP, but this doesnt generate any ARP packets.
So how would one approach this?
Thanks
Hong
hongman
03-20-2006, 04:59 PM
Still stuck on this one!
yeehawjared
03-29-2006, 02:32 PM
sometimes there really are clients on a network but you can't see them. I don't know your scenario, but sending a mass deauth causes some clients to come out of the woodwork. This happens all the time with really quiet networks.
keep your eye on airodump while it's running to see if any clients are exposed after a mass deauth.
hongman
03-29-2006, 02:39 PM
Cool, thanks for that info.
WHat is the correct command for mass deauth using Aireplay?
slice
03-29-2006, 10:09 PM
Just do attack 0 without the -c option.
hongman
03-30-2006, 08:11 AM
Ok, so you can maybe get some 'quiet' clients to appear by doing a mass deauth.
What about if there are truky no clients? Is it possible then?
hobbes
03-30-2006, 09:42 AM
Use the fake-auth attack to put a client on the network, then de-auth it and grab the SYN packet.
hongman
03-30-2006, 12:42 PM
Is SYN the same as ARP?
Digger
03-31-2006, 06:45 AM
Watch this video , it works like a charm
tested it and aproved
http://hardware-place.com/download.php?view.42
hobbes
03-31-2006, 07:03 AM
That's awsome, man, thanks for doing that.
hongman
03-31-2006, 02:27 PM
Thanks!!!
Looks like an interesting site as well!
G-Stress
03-31-2006, 06:49 PM
Yes, very good video, thanks:)
TheGreatVirus
04-01-2006, 01:40 AM
Hehe, nice video and yes nice site as well. Thank you =)
kakazza
04-05-2006, 10:03 PM
Video seems to be 404, yes I registered.
Can anyone fix it or upload it somewhere else like rapidshare?
padou
04-09-2006, 02:19 PM
The video file is no more available on this site.
Any way to have it up back ?
:o
XzifT
04-10-2006, 01:07 AM
Start aireplay with:
aireplay -1 30 -e essid -a apmac -h clientmac wifidevice
This will periodically try to reassociate with the ap every thirty seconds. I've had much better luck with using a real mac address associated with the AP as opposed to 00:11:22:33:44:55 or whatever else you care to use.
next start the normal deauth attack with:
aireplay -3 -e essid -b apmac -h client -x 512 wifidevice
you can use -x whatever you like and you can also use
aireplay -0 4 -a apmac -c clientmac wifidevice
to try to generate some arp requests...realize though that this will force you to restart the aireplay -1 command generally. With some persistence this attack is pretty easy to perform and i've actually found that using the interactive packet replay -2 is sometimes easier. Your best bet is to really read the aircrack documentation in all seriousness :)
padou
04-11-2006, 09:29 PM
Many thanks XzifT.
I will try and advise if successfull...
:cool:
n3Cre0
04-17-2006, 07:30 PM
Does this work by anyone?
I tryed this method on three different APs already.
I never got any succes.
I do the fake authentication and then the faked client shows up (however under 'Probed' the network where I associated it with doesn't appear).
Then I run the aireplay -3 attack. After like 15 minutes I get my first requests and it starts sending. However the dataflow doesn't increment...
So I don't get the data up... So no use for WEP cracking.
Then I associate with a real client to my AP and I get ARP quest (pretty fast) en then when I send the packets the dataflow now does increase.
So I don't know if you guys got any succes and maybe if you know why my faked client has't got the network it is associated with under 'Probed' in airodump?
Thnx
n3Cre0
04-25-2006, 06:24 PM
C'mon ppl someone must have tried this...
G-Stress
05-08-2006, 07:17 AM
Yea I tried once so far and with one of those dam 2WIRE's. I'm sooo determined to break into one of those, I know most of them are SBC Yahoo DSL. Anyone every successfully broken into one? They come by default with 64-bit wep encryption so that helps us out a little bit, we know it's wep 64-bit. They also have no external antenna's.
Anyway I attempted this same attack and was not even successful to associate my wifidevice. The only thing I can see stoppin me from associating successfully is mac filtering, but I'm not sure.
waqapak
05-18-2006, 04:42 PM
Do we really need an ESSID to make this work? I'm trying to crack the wireless network I setup myself and I don't have another laptop to associate it with (this is my only guy). I also turned my ssid broadcast off to make it harder for myself (sure I could just turn it back on, but what's the fun in that?). Do you always get an ESSID if you leave Kismet on long enough?
Lasqar
05-18-2006, 08:29 PM
yeah you have to have another Client conected to be able to pick up and generate traffic. or else how would you pick up the key if there is no key use?
trueblu8
05-27-2006, 01:59 AM
Yea I tried once so far and with one of those dam 2WIRE's. I'm sooo determined to break into one of those, I know most of them are SBC Yahoo DSL. Anyone every successfully broken into one? They come by default with 64-bit wep encryption so that helps us out a little bit, we know it's wep 64-bit. They also have no external antenna's.
Anyway I attempted this same attack and was not even successful to associate my wifidevice. The only thing I can see stoppin me from associating successfully is mac filtering, but I'm not sure.
Hmmm, yes those damn 2wire's, hahahaha! I've got the same problem g-stress. Anybody have any luck with these?
G-Stress
05-27-2006, 01:51 PM
Once I get my lappy fixed I will get into one of these 2WIRE's it's just a matter of time.
xbxbxc
06-05-2006, 11:48 PM
I was getting an error code 13 while sending fake authentication requests at my buddy's house. Something about this router doesn't support open system authentication. Must be Mac filtering.
baalpeteor
06-07-2006, 03:57 AM
Yea I tried once so far and with one of those dam 2WIRE's. I'm sooo determined to break into one of those, I know most of them are SBC Yahoo DSL. Anyone every successfully broken into one? They come by default with 64-bit wep encryption so that helps us out a little bit, we know it's wep 64-bit. They also have no external antenna's.
Anyway I attempted this same attack and was not even successful to associate my wifidevice. The only thing I can see stoppin me from associating successfully is mac filtering, but I'm not sure.
not to fear. Mac filtering is the easiest thing to bypass I say. Once you know a mac that you can use ( albeit a client, or maybe the AP mac will suffice?).
once you have it just type into any empty konsole:
macchanger --mac=XX:XX:XX:XX:XX:XX interfacehere
if you get an error its probably because you need to down your card first.
hope that helps ^.^
trueblu8
06-07-2006, 06:34 AM
not to fear. Mac filtering is the easiest thing to bypass I say. Once you know a mac that you can use ( albeit a client, or maybe the AP mac will suffice?).
once you have it just type into any empty konsole:
macchanger --mac=XX:XX:XX:XX:XX:XX interfacehere
if you get an error its probably because you need to down your card first.
hope that helps ^.^
Hmmm, cool. Have you gotten this to work on a 2wire router though without knowing the client mac by any chance?
croft
09-01-2006, 07:04 PM
Watch this video , it works like a charm
tested it and aproved
http://hardware-place.com/download.php?view.42
This video link doesn't work anymore. Anybody has the instructions from the site for cracking a wep without a client?
thx,
C
croft
09-12-2006, 10:33 PM
I'm using Final version with d-link usb g122.
damocles
06-21-2007, 08:20 PM
Vid is gone, who can re upload it?
c00lcarlos
06-22-2007, 12:48 AM
Thank you for your posts.
Does any-1 saved the Video from the page ? hardware-place.com site ?
or maybe someone have a mirro-page ?
thank you.
Greetings
shamanvirtuel
06-22-2007, 12:57 AM
Well.... there is plenty video on milworm and aircrack-ng sites....and in many places.....or
i will spoonfeed newbees again
if you want the complete commands...made search by yourself...lazy boys....
1 sniff APs................write down essid & bssid
2 fakeauth with ap with a reauth each 10 sec --fakeauth 10 option
3 you can now do a chopchop or a fragment attack
4 if succeed will get a keystream in xor format
5 forge an arp packet from the previous xor file with packetforge
6 replay this packet............
iv should start flying...........
pureh@te
06-22-2007, 03:57 PM
how hard is it to go to the backtrack wiki. There is already a bookmark that comes with your bt firefox browser. there is a excellent movie by mutts on wep/no client cracking. Ive recently found out from my peers though that all that is not even nesesary . all you have to do is use the aireplay -3 option and be patient. Thanx to xploits
-=Xploitz=-
06-22-2007, 05:07 PM
Ive recently found out from my peers though that all that is not even nesesary . all you have to do is use the aireplay -3 option and be patient. Thanx to xploits
Peer?? Me a freaking peer?? So thats all I am to you huh? :p
And yes patience is the key..and patience is the essence of growth says Confucius. It can take anywhere from 2 seconds to 30 minutes..depending how lucky with your timing you are with the -3 attack.
pureh@te
06-22-2007, 05:22 PM
Peer?? Me a freaking peer?? So thats all I am to you huh? :p
And yes patience is the key..and patience is the essence of growth says Confucius. It can take anywhere from 2 seconds to 30 minutes..depending how lucky with your timing you are with the -3 attack.
I though peer sounded grown up and official. oh wait Im already grown up but I forgot official:D
c00lcarlos
06-22-2007, 05:24 PM
sorry for my question.
I checked all the tutorials but it never works for me.. now i know i have to wait more time :) i canceld always after 10-15 min. thought its more easyly.
Thank you for your help
greetings
-=Xploitz=-
06-22-2007, 05:29 PM
I though peer sounded grown up and official. oh wait Im already grown up but I forgot official:D
The words "Mentor" and "Confidant" come to mind.:D
sorry for my question.
I checked all the tutorials but it never works for me.. now i know i have to wait more time :) i canceld always after 10-15 min. thought its more easyly.
Thank you for your help
greetings
No apologies necessary. Were here to help. Now you know, and knowing is half the battle. GO JOE! http://i32.photobucket.com/albums/d25/Pirate1976/Half20the20Battle20Mousepad.jpg
-=Xploitz=-
06-22-2007, 05:43 PM
how about "super double first homeboy"
LOL>....I remeber that...ok..ok...We had our fun..lets quit flooding this thread sorry super prez and Admins/. :o
AmphybiouS
07-07-2007, 02:42 AM
I cannot see the video. Can you past the new link pls?
pureh@te
07-07-2007, 02:50 AM
I cannot see the video. Can you past the new link pls?
If you cant navigate your way to the backtrack wiki I'm afraid you have the wrong distro and maby you are out of your leauge,
vBulletin® v3.7.3, Copyright ©2000-2008, Jelsoft Enterprises Ltd.