Remote Exploit Forums

Go Back   Remote Exploit Forums > Archives > BackTrack v2.0 Final > Tutorials & Guides


Tutorials & Guides Contributions welcome! Please check the rules & guidelines for posting

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-28-2006, 04:14 AM
Senior Member
 
Join Date: Jan 2006
Location: British Columbia, Canada
Posts: 192
Default Simple check for proper injection

This thread was created as a companion to the Quick Guide to Breaking WEP because it exceeded the character limit. Still, useful.

Checking for injection

If you are unsure if your card is injecting properly there is a simple test you can do. First you will need to bring your card into monitor mode (iwconfig DEV mode monitor where DEV is your wifi device. There may be additional steps involved in preparing your system for injection. Some cards do not support monitor mode, either.)

Then start wireshark (it's in the sniffers menu, or type "wireshark" into a console. It's worth noting that until recently his tool was called ethereal.) Click the button to show the capture options (second from the left, little wrench icon) and select your wifi device from the drop down menu. Check the box to update the list of packets in realtime and then start the capture. If you want to display only the deauth frames you are about to broadcast, enter the following into the display filter of wireshark (NOTE: Display filters and Capture filters are not the same thing. The display filter input box is labled "Filter:" and is located just below the options button.)

Display filter for deauth packets in wireshark

wlan.fc.type_subtype == 12

Next, in a fresh konsole or xterm window, type: aireplay -0 10 -a 01:02:03:04:05:06 DEVICE . This command will broadcast 10 deauth frames to a nonexistant AP. If all goes well the deauth packets should show up in the wireshark capture frame.


As usual, I'm open to corrections and additions, PM me if you have any.

Links

Ethereal Wireless Filter List

Original WEP Cracking Tutorial
__________________
---
Useful HowTo Threads <-- Why do people think I'm joking when I link this?

Last edited by hobbes; 11-14-2006 at 05:32 AM.
Reply With Quote
  #2 (permalink)  
Old 04-28-2006, 11:20 PM
Member
 
Join Date: Jan 2006
Posts: 91
Default

Nice job. That is usefull for those who have problem with aireplay and are unsure of what the can do to investigate further.
Reply With Quote
  #3 (permalink)  
Old 04-28-2006, 11:56 PM
Just burned his ISO
 
Join Date: Apr 2006
Posts: 4
Default

thanx for this!
Reply With Quote
  #4 (permalink)  
Old 05-18-2006, 12:53 AM
Junior Member
 
Join Date: May 2006
Posts: 9
Default

after I enter

aireplay -0 -10 -a 00:00:00:00:00 ath0

I get

please specify a BSSID (-a).

Any clue what I must be doing wrong?
Reply With Quote
  #5 (permalink)  
Old 05-18-2006, 01:02 AM
Member
 
Join Date: Feb 2006
Posts: 41
Default

Quote:
Originally Posted by Tossil
after I enter

aireplay -0 -10 -a 00:00:00:00:00 ath0

I get

please specify a BSSID (-a).

Any clue what I must be doing wrong?
Enter it. Google essid, ssid, bssid.
Reply With Quote
  #6 (permalink)  
Old 05-18-2006, 02:04 AM
Junior Member
 
Join Date: Mar 2006
Posts: 10
Default

Quote:
Originally Posted by Tossil
after I enter

aireplay -0 -10 -a 00:00:00:00:00 ath0

I get

please specify a BSSID (-a).

Any clue what I must be doing wrong?
try aireplay -0 -10 -a 00:11:22:33:44:55 ath0
Reply With Quote
  #7 (permalink)  
Old 05-18-2006, 05:46 AM
Junior Member
 
Join Date: May 2006
Posts: 9
Default

Quote:
Originally Posted by darthn
Enter it. Google essid, ssid, bssid.
Darthn, as you can see in my post I did enter a BSSID (OO:OO:OO:OO:OO:OO) as was said above. The error came after entering exactly what was said.
Reply With Quote
  #8 (permalink)  
Old 05-18-2006, 06:10 AM
Senior Member
 
Join Date: Jan 2006
Location: British Columbia, Canada
Posts: 192
Default

The MAC address must be six (6) hex characters long. As in 11:22:33:44:55:66.
__________________
---
Useful HowTo Threads <-- Why do people think I'm joking when I link this?
Reply With Quote
  #9 (permalink)  
Old 05-18-2006, 07:35 AM
Junior Member
 
Join Date: Mar 2006
Posts: 10
Default

the reason I posted the 00:11:22:33:44:55 was that I also had problems just using 0's but 00:11:22:33:44:55 worked fine
Reply With Quote
  #10 (permalink)  
Old 05-18-2006, 08:18 AM
Junior Member
 
Join Date: May 2006
Posts: 9
Default

"Next, in a fresh konsole or xterm window, type: aireplay -0 10 -a 00:00:00:00:00:00 DEVICE . This command will broadcast 10 deauth frames to a nonexistant AP. If all goes well the deauth packets should show up in the ethereal capture frame."

As stated above, entering 00:00:00:00:00:00 gave me that error. So I entered 00:11:22:33:44:55 and did not get the error I had gotten before.

After doing that, nothing came up in Ethereal, so I assume my wireless card is not injecting anything. Oh fun.... At least I know one thing thats giving me problems now. Thanks for the help.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:41 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2