|
|||||||
| BackTrack3 Howtos Add your howto articles / tutorials here. |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
MDK3's one of the best feature is to bruteforcing hideen ESSID's.it works in 2 way one we can try with every possible combination,suitable for short ESSID's or we can try using default/custom created ESSID list.I have attached shmoo group's WPA Tables ESSID with modification of some more default ESSID which I got from different forums.so now there is approx 1143 ESSID's.using MDK3 within few seconds you can get the Hidden ESSID's.
I have set the 11 chars. Essid and set it to hidden. Tested using Linksys WUSB54GC adapter and Linksys WRT54G Router. Commands: bt~#airodump-ng rausb0 open one more window #if command supplied without target -t parameter.it will bruteforce for all #hidden ESSID's in range. bt ~ # mdk3 rausb0 p -f SSID.txt -t 00:21:29:68:16:C2 SSID Wordlist Mode activated! Waiting for beacon frame from target... Sniffer thread started SSID is hidden. SSID Length is: 11. Trying SSID: linksys Trying SSID: ascend Trying SSID: <any ssid> Trying SSID: mynetwork Trying SSID: fatport Trying SSID: 2WIRE975 Trying SSID: 2WIRE186 Trying SSID: 2WIRE707 Trying SSID: 2WIRE774 Trying SSID: 2WIRE436 Packets sent: 1143 - Speed: 120 packets/sec Got response from 00:21:29:68:16:C2, SSID: "thunderbolt" Here you got hidden ESSID in less then 10 seconds.by default its speed is 300 pps.In airodump-ng window you can see that hidden essid <length: 11> has been now changed to your essid.e.g. thunderbolt. Download Essid File
__________________
Back|Track 4 Wiki Editor & Founder of Indian Cyber Army 0pen and free" d0es not mean "expl0ited and abused." Centrino Core 2 Duo,250GB HDD,Geforce 9200 GS,4 Gigs RAM,Windows 7 Ultimate,Sun Solaris 10,BackTrack 4,2003 Server,2 Cisco ASA 5520 w/ security+,Cisco 7200 Series Adv. Security IOS 12.4T,Cisco NAC,Cisco IPS 4215 5.1,6.0,Cisco MARS,Cisco ACS 4.2,NetForensic Log Analyzer,Linksys WRT54G,2 Alfa AWUS036H 500 mW cards with 16 dBi Omni Antenna |
|
|||
|
Hi
Tried using your "How to" but came up with an issue Set my AP to a 3 char SSID and disabled the SSID broadcast when i run airodump-ng the ssid length is reported as 1 which i suspect is not allowing the MDK3 command to run successfully Any ideas ? Running the VMware version of BT3 with a linksys WUSB54GC adapter AP router is SMC7904WBA |
|
|||
|
Worked like magic
used wireshark to capture packets between my apple iphone and the AP the probe reponse filter wlan.fc.type_subtype == 5 was particulary helpful in giving me the tag length of 3 and the tag interpretation of "SMC" (SSID) for my test setup as well as giving additional info such as both supported rates and extended supported rates. Highly reccomend this test if you want a better understanding of the link setup between a client and AP especially Association and Probe requests and responses - also used wlan.fc.type_subtype == 1 (assoc response) filter Thanks for your Advice as not only have i a better understanding of whats happening but also have learnt the uusefullness of wireshark |
|
|||
|
Hi my senior secure_it, may i ask u is it posibble to crack Hidden ESSID not using wordlist(dictionary list)? like crack WEP password just capture enought IVS than can easy crack that password without having any wordlist, because if the Hidden ESSID put the word are very2 difficult to guess(not a dictionary word) than our wordlist dont have this word than cannot crack already.And WPA security is it also same crack it must using wordlist, not same like WEP just capture enought IVS than can been crack. Thank u.
|
|
|||
|
Hi my Senior Tron Thank ur reply, may i ask you, if that AP ESSID is hidden than once a client connects to that AP using a valid ESSID, Than this is a GOOD chance to crack this hidden ESSID, Using what tools?how to do it? is it just using command: airodump-ng -w myfile -c 6 rausb0 , Than the hidden ESSID will apear on airodump-ng screen? Thank you very much.
|
|
||||
|
Quote:
__________________
Back|Track 4 Wiki Editor & Founder of Indian Cyber Army 0pen and free" d0es not mean "expl0ited and abused." Centrino Core 2 Duo,250GB HDD,Geforce 9200 GS,4 Gigs RAM,Windows 7 Ultimate,Sun Solaris 10,BackTrack 4,2003 Server,2 Cisco ASA 5520 w/ security+,Cisco 7200 Series Adv. Security IOS 12.4T,Cisco NAC,Cisco IPS 4215 5.1,6.0,Cisco MARS,Cisco ACS 4.2,NetForensic Log Analyzer,Linksys WRT54G,2 Alfa AWUS036H 500 mW cards with 16 dBi Omni Antenna |
|
|||
|
Quote:
So when if I try and brute force my hidden essid (7 chars - linksys) do I need to be in range of the AP for every essid try, or can I be downstairs where the signal doesn't reach? Also, can a hidden essid's length be 1 or 0 (which indicates a hidden length) when brute forcing? Thanks. |
![]() |
| Bookmarks |
| Tags |
| bruteforce, decloak, essid, hidden essid, mdk3 |
| Thread Tools | |
| Display Modes | |
|
|