![]() |
|
|||||||
| Register | Search | Today's Posts | Mark Forums Read |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Hello.
![]() Let me explain my setup first: my router is a Linksys WRT54GS using a 128bit WEP key that I want to crack. My notebook (approximately 1 meter away from the router) has a built-in Intel PRO/Wireless 2200 card (Centrino) and an MSI CB54G2 PCMCIA card (Ralink chipset). For the MSI card I am using the latest CVS drivers. I've started airodump on the Intel card and aireplay on the MSI card: Code:
aireplay -3 -b <MAC of router> -h <MAC of an associated client> ra0 Thanks. |
|
|
|
|
#2 (permalink) | |
|
SpoonfeederExtraordinaire
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
|
Quote:
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo :00475170 6E 66 65 65 64 65 72 2E nfeeder. :00475178 45 78 74 72 61 6F 72 64 Extraord :00475180 69 6E 61 69 72 65 5D 3B inaire]; :00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.].. |
|
|
|
|
|
#3 (permalink) | |
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Quote:
|
|
|
|
|
|
#4 (permalink) | |
|
SpoonfeederExtraordinaire
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
|
Quote:
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo :00475170 6E 66 65 65 64 65 72 2E nfeeder. :00475178 45 78 74 72 61 6F 72 64 Extraord :00475180 69 6E 61 69 72 65 5D 3B inaire]; :00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.].. |
|
|
|
|
|
#5 (permalink) |
|
Drunken Stumbler
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,803
|
The real trick is to try getting the nessecary IV's with no associated clients or no traffic on a client.
__________________
Never drink anything larger than your head! Scaramental Wine Taster for the Church Of WiFi Buy our books! "I reject your reality, and substitute my own!" – Adam Savage CoWF WPA Hash Tables |
|
|
|
|
#6 (permalink) | |
|
Managing the iTards.
Join Date: Dec 2002
Location: Ohio
Posts: 5,383
|
Quote:
Yea, but you just have to look at a wrt and it rolls over and pisses itself. ![]()
__________________
Atheism is a non-prophet organization. |
|
|
|
|
|
#7 (permalink) | |
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Quote:
How can I speed things up? Thanks. |
|
|
|
|
|
#8 (permalink) | |
|
SpoonfeederExtraordinaire
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
|
Quote:
Without doing any sort of packet re-injection, you should be able to collect several hundred thousand IVs (or more) in a 24 hour period, assuming the network is in use. If someone is downloading large files (CD images, for example), you could conceivably get this many IVs in several hours. All this again, without using any packet reinjection. I would guess that whatever packet you are reinjecting is simply not working.
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo :00475170 6E 66 65 65 64 65 72 2E nfeeder. :00475178 45 78 74 72 61 6F 72 64 Extraord :00475180 69 6E 61 69 72 65 5D 3B inaire]; :00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.].. |
|
|
|
|
|
#9 (permalink) |
|
Drunken Stumbler
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,803
|
Are you actually injecting packets?
Does the rate of packet capture increase when you fire up aireplay? Double check you've patched everything you need to patch for injection.
__________________
Never drink anything larger than your head! Scaramental Wine Taster for the Church Of WiFi Buy our books! "I reject your reality, and substitute my own!" – Adam Savage CoWF WPA Hash Tables |
|
|
|
|
#10 (permalink) | |||||
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Thanks for your replies.
Quote:
![]() Quote:
![]() Quote:
Quote:
Quote:
I just used the rt2500 nightly CVS tarball as 100h.org is down. What patches do I have to apply and where do I get them? |
|||||
|
|
|
|
#11 (permalink) | ||
|
Drunken Stumbler
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,803
|
Quote:
If you actually RTFM the readme for Aircrack you'll see that depending on which drivers your using (madwifi, hostap, etc) you need to patch them. Looking at the matrix of support you see: Quote:
Google will provide copies of the files you need
__________________
Never drink anything larger than your head! Scaramental Wine Taster for the Church Of WiFi Buy our books! "I reject your reality, and substitute my own!" – Adam Savage CoWF WPA Hash Tables |
||
|
|
|
|
#12 (permalink) | |
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Quote:
Code:
Installing the rt2500 driver (Ralink b/g PCI/CardBus) ifconfig ra0 down rmmod rt2500 cd /usr/src wget http://100h.org/wlan/linux/ralink/rt2500-cvs-20051112.tgz tar -xvzf rt2500-cvs-20051112.tgz cd rt2500-cvs-20051112 cd Module make && make install modprobe rt2500 Make sure to load the driver with modprobe (not insmod) and to put the card in Monitor mode before bringing the interface up. And I say it again - it is a speed issue, not a "I cannot get aireplay working at all" one. Hints still welcome. |
|
|
|
|
|
#13 (permalink) | |
|
Drunken Stumbler
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,803
|
Quote:
Also, Have you tried any other wireless cards/drivers with aireplay? Not haveing a ralink card handy I can't test it's replay speed. It may be that the ralink chipset can't do it very fast.
__________________
Never drink anything larger than your head! Scaramental Wine Taster for the Church Of WiFi Buy our books! "I reject your reality, and substitute my own!" – Adam Savage CoWF WPA Hash Tables |
|
|
|
|
|
#14 (permalink) | |||
|
Registered Member
Join Date: Feb 2006
Posts: 11
|
Quote:
Quote:
).Quote:
|
|||
|
|
|
|
#15 (permalink) | |
|
I amuse you?
Join Date: Dec 2003
Posts: 9,127
|
Quote:
What is the FCCID # of your card? I'd like to see if there are any weird revisions. |
|
|
|