View Single Post
Old 07-01-2005   #6 (permalink)
devine
Emergence
 
Join Date: Jul 2004
Location: Paris
Posts: 389
Quote:
Originally Posted by scope
Grabbed a packet, faked authentication, tried to chopchop the packet. chopchop and aireplay -4 work, but the keystream differs.
Ok. Could you send me the two keystreams ? And also the original packet and the WEP key if possible.

Quote:
Originally Posted by scope
Fake authentication works great on most aps I tested. But I got several ones where it didnīt work.
Yes, that is a known problem that lies within injection in monitor mode. Basically aireplay can't send ACK frames fast enough, the max. delay is 0.3 ms which is really short. Most APs will let the association work even if they don't receive the ACKs, but others don't.

Quote:
Originally Posted by scope
If I use aireplay-chop in combination with fake authentication it keeps saying it got an deauth packet from the ap and stops, though chopchop does the job in that situation.
Could you also send me the decrypted packet and the keystream generated by chopchop in this situation ?

Thanks!

-- Christophe
devine is offline   Reply With Quote