NetStumbler.org Forums

Go Back   NetStumbler.org Forums > Software > Unix/Linux
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 08-15-2005   #1 (permalink)
renderman
Drunken Stumbler
 
renderman's Avatar
 
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,862
WRT54G Spoofed AP Guide

For Defcon, I developed a few tricks that I hoped would give my team an edge in the wardriving contest, including an easy way to make my own Spoofed target AP's to confuse and distract other teams.

It took some research, but I now have the instructions nessecary for changing the MAC on the wireless side to whatever you want! Coupled with a matching SSID you now have your own embedded 'Evil Twin' (hate that term), spoofed AP for doing whatever the hell it is you want to do. No more HostAP mode and laptops, just a small blue box, easily hidden inside a teddy bear

Personally, I see potential of extending this research further and ending up with my own embedded airsnarf box, but my scripting skills suck

For now, have fun with what I have posted at http://www.renderlab.net/projects/wr...54g-spoof.html

As usual, questions, comments and improvements are welcome.

Mod: Sticky again?

Last edited by renderman : 08-15-2005 at 03:39 PM.
renderman is offline   Reply With Quote
Old 08-15-2005   #2 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,819
Quote:
Originally Posted by renderman
Mod: Sticky again?
Done!

And just for the record : This confirms it, I'm NEVER EVER going to accept any gifts from you, without having it x-rayed, contained in a faraday cage, and exposed to the effects of an EMP weapon first.

Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....

Last edited by Dutch : 08-15-2005 at 03:46 PM.
Dutch is offline   Reply With Quote
Old 08-15-2005   #3 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,229
I think a good thing for you to work on would be a self charging battery powered concealed AP. You can get solar panels rather cheap now, have them power a charging circuit to some lithium ion or NIMH AA batteries. I bet you could get something to work.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary.

Last edited by streaker69 : 08-15-2005 at 03:44 PM.
streaker69 is offline   Reply With Quote
Old 08-15-2005   #4 (permalink)
renderman
Drunken Stumbler
 
renderman's Avatar
 
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,862
I had the ones at Defcon wired up to some rechargeable 2.3ah lead acid batteries. Ran for at least 7 hours in full AP mode.

It would'nt be a stretch to throw in a charging circuit and some solar panels, however, my post Defcon budget is <$0 as I spent way to much money down there and I need to pull some major overtime to cover the bills that piled up while I was away, so no hardware purchases for a while. Fortunatly the vegetable crisper is still full of Guiness

On another note, anyone care to help get a thttp server to capture logins ala airsnarf and really make this deadly?
renderman is offline   Reply With Quote
Old 08-15-2005   #5 (permalink)
Dutch
Humourless EuroMod.
 
Dutch's Avatar
 
Join Date: Mar 2004
Location: City of Mermaids, Denmark
Posts: 6,819
Quote:
Originally Posted by renderman
I had the ones at Defcon wired up to some rechargeable 2.3ah lead acid batteries. Ran for at least 7 hours in full AP mode.

It would'nt be a stretch to throw in a charging circuit and some solar panels, however, my post Defcon budget is <$0 as I spent way to much money down there and I need to pull some major overtime to cover the bills that piled up while I was away, so no hardware purchases for a while. Fortunatly the vegetable crisper is still full of Guiness

On another note, anyone care to help get a thttp server to capture logins ala airsnarf and really make this deadly?
I'll have a go at it. PM me with what you want me to do.

Dutch
__________________
All your answers are belong to Google. SEARCH DAMMIT!
Warning. Warning.
Low C8H10N4O2 level detected. Operator halted....
Dutch is offline   Reply With Quote
Old 08-15-2005   #6 (permalink)
streaker69
Psychic Amish Stumbler
 
streaker69's Avatar
 
Join Date: Jul 2004
Location: Virginville, BlueBall, Bird In Hand, Intercourse, Paradise, PA
Posts: 12,229
Quote:
Originally Posted by renderman
I had the ones at Defcon wired up to some rechargeable 2.3ah lead acid batteries. Ran for at least 7 hours in full AP mode.

It would'nt be a stretch to throw in a charging circuit and some solar panels, however, my post Defcon budget is <$0 as I spent way to much money down there and I need to pull some major overtime to cover the bills that piled up while I was away, so no hardware purchases for a while. Fortunatly the vegetable crisper is still full of Guiness

On another note, anyone care to help get a thttp server to capture logins ala airsnarf and really make this deadly?
Can't help ya with the last question, but let me know if you're looking for parts to work with. I have a couple of good cheap sources for things. I found some solar panels for around $4.00 and some 2200mah NiMH AA's for $2.75 each.
__________________
Treat your gun like your genitals, only whip it out when it's absolutely necessary.
streaker69 is offline   Reply With Quote
Old 08-16-2005   #7 (permalink)
renderman
Drunken Stumbler
 
renderman's Avatar
 
Join Date: Jun 2002
Location: Anywhere but Utah
Posts: 1,862
http://airsnarf.shmoo.com/rogue_squadron/index.html

Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck, Fuck.

You know, I really should have been watching Beetles talk at Blackhat. Could have saved myself some trouble. To many damn secret projects.

Quote:
"Airsnarf: Rogue Squadron" is a proof-of-concept rogue AP firmware for the Linksys WRT54G, based on the Ewrt firmware v0.3 beta 1 by Portless Networks, which is based on the Linksys 3.01.3 codebase. With this firmware you can quickly turn a Linksys WRT54G into a rogue access point that "authenticates" users and "provides" Internet access.

Last edited by renderman : 08-16-2005 at 12:50 PM.
renderman is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 12:19 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.