![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#77 (permalink) | ||
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
Quote:
|
||
|
|
|
|
#78 (permalink) | ||
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
Quote:
Thanks very much for all the testing you've done.-- Christophe |
||
|
|
|
|
#79 (permalink) |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
I have a question about traffic generation :
How can I generate traffic when I don't have an IP address for my wireless card and can not use aireplay ? is there any option in the ping command to specify the broacast ping from a wireless interface ? ping -b but how to precise I want to use my eth1 interface. Moreover if I can send ping over the air without having any IP address , will the replies be encrypted ? I'm a bit confused about the generation of traffic when we just know the SSID. |
|
|
|
|
#81 (permalink) | |
|
Asshole Emeritus
Join Date: May 2003
Location: S.E. VA.
Posts: 5,913
|
Quote:
![]()
__________________
"Benjamin is nobody's friend. If Benjamin were an ice cream flavor, he'd be pralines and dick." Sons of Confederate Veterans |
|
|
|
|
|
#83 (permalink) | |
|
Registered Member
Join Date: Jun 2004
Posts: 67
|
Quote:
I mean, if the wlan is wep-protected, then the packets you send must be encrypted in order to be accepted by the other hosts. So you cannot use tools like ping because as your wlan card driver does not know the wep key, the ICMP won't be encrypted and therefore will be ignored by other hosts. It's clear that without the wep key you cannot create custom packets, but you can REINJECT logged ones. You can sniff the network and get an encrypted packet. You do not know what kind of packet is, it's headers or it's payload as it is encrypted, but you can reinject it in the network. So, if you can capture a packet, for example an arp-request, and reinject it in the network, destination host will believe that is was sent by the original sender and will produce a response. That happens with arp, tcp-SYN, icmp, and so on. Finally as you do not know which packets are usefull (arp, icmp) because they are encrypted, the only way to guess them is using their size. As far as I know that's what aireplay uses. But I have one question... Is there any way to know if a specific packets have been replayed... in other words... can an IDS manage to detect the attack? |
|
|
|
|
|
#84 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
![]() |
|
|
|
|
|
#85 (permalink) | ||
|
Registered Member
Join Date: Aug 2004
Location: Paris, France
Posts: 8
|
Quote:
![]() Maybe someone could make some tests for me ? Quote:
![]() By the way, I think the graphs depends on how IVs are distribued. PS : Most of added features were done quickly as I wanted to test as soon as possible. PS2 : This forum only support zip attachement, so I've zipped the tarball. Last edited by b0nk : 08-25-2004 at 05:03 AM. |
||
|
|
|
|
#86 (permalink) | |
|
Banned in DC
Join Date: Jul 2004
Posts: 102
|
Quote:
Packet reinjection is quite laborious. Let's see if reality sticks to theory... PS: b0nk, read the forum rules/FAQ before posting. |
|
|
|
|
|
#87 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
|
|
|
|
|
|
#88 (permalink) | |
|
Registered Member
Join Date: Aug 2004
Location: Paris, France
Posts: 8
|
Quote:
Can you create a 1.3-1.4 diff patch ? Would be easier for me to merge my code to the new aircrack ![]() |
|
|
|
|
|
#89 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|