Remote Exploit Forums

Go Back   Remote Exploit Forums > Archives > BackTrack 3 Final > BackTrack3 Howtos


BackTrack3 Howtos Add your howto articles / tutorials here.

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-31-2008, 10:20 AM
secure_it's Avatar
Senior Member
 
Join Date: Dec 2007
Location: 在後面之間|軌道4 & Fwd|軌道4
Posts: 861
Send a message via Yahoo to secure_it Send a message via Skype™ to secure_it
Thumbs up How to bruteForce Hidden ESSID Using MDK3

MDK3's one of the best feature is to bruteforcing hideen ESSID's.it works in 2 way one we can try with every possible combination,suitable for short ESSID's or we can try using default/custom created ESSID list.I have attached shmoo group's WPA Tables ESSID with modification of some more default ESSID which I got from different forums.so now there is approx 1143 ESSID's.using MDK3 within few seconds you can get the Hidden ESSID's.
I have set the 11 chars. Essid and set it to hidden.
Tested using Linksys WUSB54GC adapter and Linksys WRT54G Router.


Commands:

bt~#airodump-ng rausb0

open one more window

#if command supplied without target -t parameter.it will bruteforce for all #hidden ESSID's in range.

bt ~ # mdk3 rausb0 p -f SSID.txt -t 00:21:29:68:16:C2

SSID Wordlist Mode activated!

Waiting for beacon frame from target...
Sniffer thread started

SSID is hidden. SSID Length is: 11.
Trying SSID: linksys
Trying SSID: ascend
Trying SSID: <any ssid>
Trying SSID: mynetwork
Trying SSID: fatport
Trying SSID: 2WIRE975
Trying SSID: 2WIRE186
Trying SSID: 2WIRE707
Trying SSID: 2WIRE774
Trying SSID: 2WIRE436
Packets sent: 1143 - Speed: 120 packets/sec
Got response from 00:21:29:68:16:C2, SSID: "thunderbolt"


Here you got hidden ESSID in less then 10 seconds.by default its speed is 300 pps.In airodump-ng window you can see that hidden essid <length: 11> has been now changed to your essid.e.g. thunderbolt.


Download Essid File


__________________
Back|Track 4 Wiki Editor & Founder of Indian Cyber Army
0pen and free" d0es not mean "expl0ited and abused."


Centrino Core 2 Duo,250GB HDD,Geforce 9200 GS,4 Gigs RAM,Windows 7 Ultimate,Sun Solaris 10,BackTrack 4,2003 Server,2 Cisco ASA 5520 w/ security+,Cisco 7200 Series Adv. Security IOS 12.4T,Cisco NAC,Cisco IPS 4215 5.1,6.0,Cisco MARS,Cisco ACS 4.2,NetForensic Log Analyzer,Linksys WRT54G,2 Alfa AWUS036H 500 mW cards with 16 dBi Omni Antenna


Reply With Quote
  #2 (permalink)  
Old 08-12-2008, 12:02 AM
Junior Member
 
Join Date: Feb 2008
Location: Melbourne, Australia
Posts: 20
Default

Hi

Tried using your "How to" but came up with an issue
Set my AP to a 3 char SSID and disabled the SSID broadcast
when i run airodump-ng the ssid length is reported as 1 which i suspect is not allowing the MDK3 command to run successfully

Any ideas ?

Running the VMware version of BT3 with a linksys WUSB54GC adapter
AP router is SMC7904WBA
Reply With Quote
  #3 (permalink)  
Old 08-12-2008, 02:47 AM
secure_it's Avatar
Senior Member
 
Join Date: Dec 2007
Location: 在後面之間|軌道4 & Fwd|軌道4
Posts: 861
Send a message via Yahoo to secure_it Send a message via Skype™ to secure_it
Thumbs up

Quote:
Originally Posted by Bestia View Post
Hi

Tried using your "How to" but came up with an issue
Set my AP to a 3 char SSID and disabled the SSID broadcast
when i run airodump-ng the ssid length is reported as 1 which i suspect is not allowing the MDK3 command to run successfully

Any ideas ?

Running the VMware version of BT3 with a linksys WUSB54GC adapter
AP router is SMC7904WBA
When the length is 0 or 1, it means the AP does not reveal the actual length and the real length could be any value.when this kind of condition occure then there are 3 methods either wait for a wireless client to authenticate with AP or deauth exist Wireless Client or use these wireshark filters to capture the packets.

wlan.fc.type_subtype == 0 (association request)
wlan.fc.type_subtype == 4 (probe request)
wlan.fc.type_subtype == 5 (probe response)let me know if it works.
__________________
Back|Track 4 Wiki Editor & Founder of Indian Cyber Army
0pen and free" d0es not mean "expl0ited and abused."


Centrino Core 2 Duo,250GB HDD,Geforce 9200 GS,4 Gigs RAM,Windows 7 Ultimate,Sun Solaris 10,BackTrack 4,2003 Server,2 Cisco ASA 5520 w/ security+,Cisco 7200 Series Adv. Security IOS 12.4T,Cisco NAC,Cisco IPS 4215 5.1,6.0,Cisco MARS,Cisco ACS 4.2,NetForensic Log Analyzer,Linksys WRT54G,2 Alfa AWUS036H 500 mW cards with 16 dBi Omni Antenna


Reply With Quote
  #4 (permalink)  
Old 08-17-2008, 06:07 AM
Junior Member
 
Join Date: Feb 2008
Location: Melbourne, Australia
Posts: 20
Default

Worked like magic

used wireshark to capture packets between my apple iphone and the AP
the probe reponse filter wlan.fc.type_subtype == 5 was particulary helpful in giving me the tag length of 3 and the tag interpretation of "SMC" (SSID) for my test setup as well as giving additional info such as both supported rates and extended supported rates.

Highly reccomend this test if you want a better understanding of the link setup between a client and AP especially Association and Probe requests and responses - also used wlan.fc.type_subtype == 1 (assoc response) filter

Thanks for your Advice as not only have i a better understanding of whats happening but also have learnt the uusefullness of wireshark
Reply With Quote
  #5 (permalink)  
Old 08-18-2008, 02:50 PM
Junior Member
 
Join Date: Dec 2007
Posts: 9
Smile Is it posibble to crack hidden ESSID not using wordlist?

Hi my senior secure_it, may i ask u is it posibble to crack Hidden ESSID not using wordlist(dictionary list)? like crack WEP password just capture enought IVS than can easy crack that password without having any wordlist, because if the Hidden ESSID put the word are very2 difficult to guess(not a dictionary word) than our wordlist dont have this word than cannot crack already.And WPA security is it also same crack it must using wordlist, not same like WEP just capture enought IVS than can been crack. Thank u.
Reply With Quote
  #6 (permalink)  
Old 08-18-2008, 02:52 PM
=Tron='s Avatar
Senior Member
 
Join Date: Apr 2008
Location: The land of a thousand lakes
Posts: 2,035
Default

Quote:
Originally Posted by tiong View Post
...is it posibble to crack Hidden ESSID not using wordlist(dictionary list)? like crack WEP password just capture enought IVS than can easy crack that password without having any wordlist...
No, but it can be intercepted in clear-text once a client connects to the AP using a valid ESSID.
__________________
-Monkeys are like nature's humans.
Reply With Quote
  #7 (permalink)  
Old 08-18-2008, 03:09 PM
Junior Member
 
Join Date: Dec 2007
Posts: 9
Smile How to intercepted in clear-text once a client connects to the AP using a valid ESSID

Hi my Senior Tron Thank ur reply, may i ask you, if that AP ESSID is hidden than once a client connects to that AP using a valid ESSID, Than this is a GOOD chance to crack this hidden ESSID, Using what tools?how to do it? is it just using command: airodump-ng -w myfile -c 6 rausb0 , Than the hidden ESSID will apear on airodump-ng screen? Thank you very much.
Reply With Quote
  #8 (permalink)  
Old 08-18-2008, 03:17 PM
=Tron='s Avatar
Senior Member
 
Join Date: Apr 2008
Location: The land of a thousand lakes
Posts: 2,035
Default

Quote:
Originally Posted by tiong View Post
is it just using command: airodump-ng -w myfile -c 6 rausb0 , Than the hidden ESSID will apear on airodump-ng screen? Thank you very much.
That is absolutely correct.
__________________
-Monkeys are like nature's humans.
Reply With Quote
  #9 (permalink)  
Old 08-19-2008, 06:42 AM
secure_it's Avatar
Senior Member
 
Join Date: Dec 2007
Location: 在後面之間|軌道4 & Fwd|軌道4
Posts: 861
Send a message via Yahoo to secure_it Send a message via Skype™ to secure_it
Post

Quote:
Originally Posted by tiong View Post
Hi my senior secure_it, may i ask u is it posibble to crack Hidden ESSID not using wordlist(dictionary list)? like crack WEP password just capture enought IVS than can easy crack that password without having any wordlist, because if the Hidden ESSID put the word are very2 difficult to guess(not a dictionary word) than our wordlist dont have this word than cannot crack already.And WPA security is it also same crack it must using wordlist, not same like WEP just capture enought IVS than can been crack. Thank u.
You can use the mdk3 p -t <BSSID> -b<character set> for bruteforcing the ESSID but its recommend for short SSID like 1 to 7 chars as it takes lot of time.
__________________
Back|Track 4 Wiki Editor & Founder of Indian Cyber Army
0pen and free" d0es not mean "expl0ited and abused."


Centrino Core 2 Duo,250GB HDD,Geforce 9200 GS,4 Gigs RAM,Windows 7 Ultimate,Sun Solaris 10,BackTrack 4,2003 Server,2 Cisco ASA 5520 w/ security+,Cisco 7200 Series Adv. Security IOS 12.4T,Cisco NAC,Cisco IPS 4215 5.1,6.0,Cisco MARS,Cisco ACS 4.2,NetForensic Log Analyzer,Linksys WRT54G,2 Alfa AWUS036H 500 mW cards with 16 dBi Omni Antenna


Reply With Quote
  #10 (permalink)  
Old 08-26-2008, 06:54 AM
Member
 
Join Date: Jul 2008
Posts: 56
Default

Quote:
Originally Posted by secure_it View Post
You can use the mdk3 p -t <BSSID> -b<character set> for bruteforcing the ESSID but its recommend for short SSID like 1 to 7 chars as it takes lot of time.

So when if I try and brute force my hidden essid (7 chars - linksys) do I need to be in range of the AP for every essid try, or can I be downstairs where the signal doesn't reach?

Also, can a hidden essid's length be 1 or 0 (which indicates a hidden length) when brute forcing?

Thanks.
Reply With Quote
Reply

Bookmarks

Tags
bruteforce, decloak, essid, hidden essid, mdk3

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:25 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2