![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#93 (permalink) | |
|
Registered Member
Join Date: Jun 2004
Posts: 67
|
Quote:
I saw somewhere a tool that implements this |
|
|
|
|
|
#94 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
|
|
|
|
|
|
#95 (permalink) | |
|
Registered Member
Join Date: Sep 2002
Posts: 310
|
Quote:
|
|
|
|
|
|
#96 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
![]() http://www.cr0.net:8040/code/network/aircrack-1.4.tgz |
|
|
|
|
|
#97 (permalink) | |
|
Registered Member
Join Date: Jun 2004
Posts: 67
|
Quote:
In fact you only need a big known (plaintext) packet to be able to create any custom encrypted packet using the same IV and wihout having the key. That is because if you know the plaintext and the cyphertext you can derive the keystream for this specific IV. With this keystream you can encrypt/decrypt anything with this IV. This way there is no need to crack the key. Only problem is that with one only packet you only can encrypt/decrypt for this IV. For sending packets it is not a problem as the sender is who select the IV. But for decrypting packets you need a known (plaintext) packet for each IV. That's 2^24 It is not so complicated to make this known plain-text. You can for example inject some packet in the wlan from internet (it will be encrypted by the AP), or guess some packet by trafic analysis. |
|
|
|
|
|
#99 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
can we imagine if we have a big known (plaintext paquet) to spoof the IP/MAC address of the access point and to build a crafted broadcast ping encrypted packet ? so that clients with respond to it and generate other encrypted packets... |
|
|
|
|
|
#100 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
why is chopper included in aircrack-1.4 ? how do we have to install it (chopper.sh) and use it ... you should write an INSTALL file ;-) |
|
|
|
|
|
#101 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
I found three little bugs in aircrack-1.4 - the displayed SSID is not always good as the length of the SSID can be longer that what aircrack displays..you should use a longer length for the variable. - it seems that only active networks are shown .. contrary to Kismet, you don't show previous discovered AP which are not active... - I could not leave airodump in a proper way |
|
|
|
|
|
#102 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
* The essid is truncated to 20 characters to fit in a 80 column display. Indeed, when the window size is larger the full essid (32 bytes) can be displayed. I've added this in my TODO list. * After 2mn of inactivity, the discovered APs are hidden; this feature is especially helpful when wardriving. Note that when you exit airodump, it saves the complete list of detected Access Points in CSV format. * airodump detects when the user presses Ctrl-C and exits gracefully. |
|
|
|
|
|
#103 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
|
|
|
|
|
|
#104 (permalink) | |
|
Emergence
Join Date: Jul 2004
Location: Paris
Posts: 389
|
Quote:
![]() |
|
|
|
|
|
#105 (permalink) | |
|
Wireless Auditor
Join Date: Jun 2004
Location: Paris, France
Posts: 175
|
Quote:
and what do you think of what I said earlier devine ? |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|