NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Mac OS
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 03-24-2005   #1 (permalink)
ddwyer50
Registered Member
 
Join Date: Mar 2005
Posts: 3
MacOS and aircrack & aireplay

Hello All,

I have been doing some research into wireless sniffing and packet analysis. I have a 12" PowerBook with an AirPort Extreme card (waste). I just picked up a D-Link DWL-122, which worked like a champ on my system. I have installed KisMAC, Ethereal (with Fink), and have also come across a aircrack binary for PPC. Nice.

I can't seem to get a (precompiled) copy of aireplay or chopchop for PPC. I dowloaded the source and tried to 'make' but that didn't work. So my question is this: is there a PPC precompiled binary out there somewhere? Is it possible for me to compile it myself? If so, how?

Thanks!

Last edited by ddwyer50 : 03-24-2005 at 11:18 PM.
ddwyer50 is offline   Reply With Quote
Old 03-25-2005   #2 (permalink)
Kronk
Registered Member
 
Join Date: Jul 2004
Posts: 13
Unless we get wireless driver support, aireplay w/ chopchop won't work under MacOS X. The latest aireplay beta works well under LinuxPPC (Yellowdog Linux), so you could give that a try.

Also, give the latest alpha of KisMAC (0.2r60). It is currenly only available in source form, but here is a link to the compiled version.

http://www.macunix.net/KisMAC_Alpha/

It has the same functionality as Aircrack 2.1 plus you only need a single Prism2 device to perform reinjection attacks. Since the original Aircrack code made it into this version of KisMAC, adding chopchop should be easy as well.
Kronk is offline   Reply With Quote
Old 03-25-2005   #3 (permalink)
ddwyer50
Registered Member
 
Join Date: Mar 2005
Posts: 3
Thanks for the info. The new version looks cool.

I am wondering though...Lets say I fire up Kismac, and it starts scanning. I find a couple of networks. Great. Now, I decide to double click on my network, to get more detailed info about it.

From here, I can see packet being logged. The "Unique IV's" start counting. However, the "Inj. Packets" stays at zero. I click "Deauthenticate" and then "Inj. Packets" starts to go up. Is this packet injection? I didn't think Deauthenticate would affect Injected Packets.

Then I click Inject. What I thought was that when I did this, the "Unique IV's" would start accumulating at a much higher rate, due to the packet injection. This does not happen. In fact, I get no indication that the packet injection is even happening. Can I verify this? Isn't injection supposed to make Unique IV's climb at a faster rate? I have looked into Kismac's documentation, but it's a little sketchy.

Thanks!
ddwyer50 is offline   Reply With Quote
Old 03-26-2005   #4 (permalink)
Kronk
Registered Member
 
Join Date: Jul 2004
Posts: 13
The current packet injection in KisMAC is based on ARP replay. The injectable packets correspond to possible ARP packets, based on the size of the packet. When an AP client reauthenticates, an ARP packet is generated during the IP address assignment process, usually DHCP.

On most APs, especially those with Windows clients, you shouldn't have to deauthenticate. I usually see a dozen or so injectable packets within a few minutes. Not all APs are susceptable to this attack and what you are seeing may mean the AP is not susceptable to a replay attack or you haven't captured the right injectable packets. You just have to test it. KisMAC may also still have some bugs, so you may need to quit and restart it a few times during the process.

In my tests, once I had the right injectable packet the Unique IVs climbed at a tremendous rate. I had enough packets to crack the WEP key in about 15 minutes.

The susceptability to ARP replay attacks is exactly why chopchop is used. You use this tool to brute force crack a single packet, get the IP and data information and forge your own injectable packet.
Kronk is offline   Reply With Quote
Old 03-26-2005   #5 (permalink)
ddwyer50
Registered Member
 
Join Date: Mar 2005
Posts: 3
Kronk, you are the man.

I partitioned my PowerBook last night and am going to install Linux on it today (Ubuntu or YellowDog I think) so I can use more wireless tools.

Thanks.
ddwyer50 is offline   Reply With Quote
Old 03-28-2005   #6 (permalink)
catherineburlow
Registered Member
 
Join Date: Jul 2004
Posts: 4
About injection

Sorry I'm only an advanced macosx user but I'm still unable to use an entire linux system.... Just a question since I cannot use another thing than kismac. Do yu mean it i posible to reinject packets with only an apple airprt card. Are you sure you don't use airport+pmcia???

Just wanting to try to inject packets to see if I'm able to crack the wep. Eager to do it.

Special kisses from barcelona city
Catherine
catherineburlow is offline   Reply With Quote
Old 03-28-2005   #7 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,813
Quote:
Originally Posted by catherineburlow
Special kisses from barcelona city
Catherine
I've experienced and know what French Kissing is, but Spanish Kissing ? Using the tongue on a bull ?

Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....
Dutch is offline   Reply With Quote
Old 03-28-2005   #8 (permalink)
Barry
Managing the iTards.
 
Barry's Avatar
 
Join Date: Dec 2002
Location: Ohio
Posts: 5,383
Quote:
Originally Posted by Dutch
I've experienced and know what French Kissing is, but Spanish Kissing ? Using the tongue on a bull ?

Dutch

Hey, hey! I've seen what happens to the bull. No Spanish kisses for me!!
__________________
Atheism is a non-prophet organization.
Barry is offline   Reply With Quote
Old 03-28-2005   #9 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,813
Quote:
Originally Posted by Barry
Hey, hey! I've seen what happens to the bull. No Spanish kisses for me!!
I once went to Spain on vacation, and actually ate at a very good restaurant just next to a bullfighting arena.
They served a very good dish, called "Cojones Del Toro" or something like that. Two big and very tender pieces of meat, in an absolutely fabulous sauce.
The second time I went to that restaurant, and ordered the same meal, I was severely disappointed though. The pieces of meat were only a quarter size compared to the first time.

When I complained, the waiter just looked and me and said : "Senor, the bull doesn't allways loose..."



Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....
Dutch is offline   Reply With Quote
Old 04-04-2005   #10 (permalink)
Tullebukk
Registered Member
 
Join Date: Apr 2005
Posts: 1
I now why we can`t use airplay on a mac. but dose anybody have a version of aircrack, the program to break the wep key for os X. you dont need a driver to run that.
Tullebukk is offline   Reply With Quote
Old 04-04-2005   #11 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 11,839
Quote:
Originally Posted by Tullebukk
I now why we can`t use airplay on a mac. but dose anybody have a version of aircrack, the program to break the wep key for os X. you dont need a driver to run that.
Working on a school project for cracking WEP?
__________________
"One of these days, I'm going to cut you to pieces."

If you're offended by this post, please feel free to report it to one of the many helpful moderators of this forum.

Thank you.
streaker69 is offline   Reply With Quote
Old 04-04-2005   #12 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,813
Quote:
Originally Posted by streaker69
Working on a school project for cracking WEP?
Damn you.. Fifth keyboard this week. You are doing it on purpose *sigh*

Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....
Dutch is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 01:39 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.