Sunday, March 14, 2010

Network infrastructure

Network hubs
In a typical office network, a strand of wiring similar to phone cable is run
from each computer to a central location, such as a phone closet, where each
wire is connected to a network hub. The network hub, similar conceptually to
the hub of a wheel, receives signals transmitted by each computer on the network
and sends the signals out to all other computers on the network.

Bridges
A network bridge provides a pathway for network traffic between networks or
segments of networks. A device that connects a wireless network segment to
a wired network segment is a type of network bridge. In larger networks, network
bridges are sometimes used to connect networks on different floors in
the same building or in different buildings. In a wireless home network, the
device that manages the wireless network, an access point, often acts as a
bridge between a wireless segment of the network and a wired segment.

Hubs and switches
Networks transmit data in bundles called packets. Along with the raw information
that’s being transmitted, each packet also contains the network
address of the computer that sent it and the network address of the recipient
computer. Network hubs send packets indiscriminately to all ports of all computers
connected to the hub.
A special type of hub called a switched hub examines each packet, determines
the addressee and port, and forwards the packet only to the computer and port
to which it is addressed. Most often, switched hubs are just called switches.
A switch reads the addressee information in each packet and sends the packet
directly to the segment of the network to which the addressee is connected.
Packets that aren’t addressed to a particular network segment are never
transmitted over that segment, and the switch acts as a filter to eliminate
unnecessary network traffic. Switches make more efficient use of the available
transmission bandwidth than standard hubs and therefore offer higher
aggregate throughput to the devices on the switched network.

Routers
Over a large network and on the Internet, a router is analogous to a superefficient
postal service — reading the addressee information in each data
packet and communicating with other routers over the network or Internet to
determine the best route for each packet to take. Routers can be a standalone
device, but more often, home networks use a device known as a cable/(digital
subscriber line) DSL router. This type of router — which marries a cable or DSL
modem and a router — uses a capability called Network Address Translation
(NAT) to enable all the computers on a home network to share a single
Internet address on the cable or DSL network. Such routers also exist for
satellite and dialup connections. Generically, these are called WAN routers
because they have access to your wide area network connection, whether it’s
broadband or dialup.

Workstations and servers

Each computer in your home that’s attached to a network is a workstation, also
sometimes referred to as a client computer. The Windows operating system
(OS) refers to the computers residing together on the same local area network
as a workgroup. A Windows-based computer network enables the workstations
in a workgroup to share files and printers that are visible through the Network
Neighborhood (or My Network Places). Home networks based on the Apple
Macintosh OS offer the same capability. On a Mac, all the computers on the
network are called a network neighborhood.

File server: A file server makes storage space on hard disks or some
other type of storage device available to workstations on the network.
Home networks seldom have a file server because each computer typically
has enough storage space to store the files created on that computer.
Common in-home applications of a file server today are consumer
devices such as Yamaha’s MusicCast (www.yamaha.com; $2,000) or
Turtle Beach Systems’ AudioTron (www.turtlebeach.com; $269) MP3
servers that enable you to play your MP3s over your stereo wirelessly.
Print server: A print server is a computer or other device that makes it
possible for the computers on the network to share one or more printers.
You won’t commonly find a print server in a home network, but
some wireless networking equipment comes with a print server feature
built in, which turns out to be very handy.
E-mail server: An e-mail server is a computer that provides a system for
sending e-mail to users on the network. You might never see an e-mail
server on a home network. Most often, home users send e-mail through
a third-party service, such as America Online (AOL), EarthLink, MSN
Hotmail, Yahoo!, and so on.

DHCP server: Every computer on a network, even a home network,
must have its own unique network address in order to communicate
with the other computers on the network. A Dynamic Host Configuration
Protocol (DHCP) server automatically assigns a network address to
every computer on a network. You most often find DHCP servers in
another device like a router or an AP.
There are many types of client computers — network-aware devices — that
you can find on your network, too. Some examples include
Gaming consoles: Microsoft’s Xbox (www.xbox.com), Sony PlayStation 2
(www.playstation.com), and Nintendo’s GameCube (www.nintendo.
com) have adapters for network connections or multi-player gaming and
talking to other players while gaming. Cool! Read more about online
gaming in Chapter 12.

Wireless network cameras: Panasonic’s KX-HCM250 and KX-HCM270
Network Cameras (www.panasonic.com/consumer_electronics/
gate/cameras.asp) enable you to not only view your home from when
away but also pan, tilt, scan, zoom, and so on your way around the
home. Now that’s a nanny-cam.

MP3 players: Yamaha’s MusicCAST interactive wireless home music network
system (www.yamaha.com) enables you to use wireless technology
to stream music files throughout your home. The system uses a main
server (about $2,000), which stores your CDs in the MP3 (or other) electronic
format, and a series of receivers or clients (about $800) in remote
rooms for playing back music. You can have one in each room — if you
can afford it!

Choosing Wireless Home Networking Equipment

Access point: At the top of the list will be at least one wireless access
point (AP), also sometimes called a base station. An AP acts like a wireless
switchboard that connects wireless devices on the network to each
other and to the rest of the network. You gotta have one of these to createa wireless home network. They range in price from about $100 to $300,
with prices quickly coming down. You can get APs from many leading
vendors in the marketplace, including Apple (www.apple.com), D-Link
(www.d-link.com), Linksys (www.linksys.com), NETGEAR (www.
netgear.com), and Siemens/Efficient Networks (www.speedstream.
com). We give you a long list of vendors in Chapter 20, so check that out
when you go to buy your AP.
For wireless home networks, the best AP value is often an AP that’s bundled
with other features. The most popular APs for home use also come
with one or more of the following features:
• Network hub or switch: A hub connects wired PCs to the network.
A switch is a “smarter” version of a hub that speeds up network
traffic. (We talk more about the differences between hubs and
switches in Chapter 2.)
• DHCP server: A Dynamic Host Configuration Protocol (DHCP)
server assigns network addresses to each computer on the network;
these addresses are required for the computers to communicate.
• Network router: A router enables multiple computers to share a
single Internet connection. The network connects each computer
to the router, and the router is connected to the Internet through a
broadband modem.
• Print server: Use a print server to add printers directly to the network
instead of attaching a printer to each computer on the
network.
In Figure 1-3, you can see an AP that also bundles in a network router,
switch, and DHCP server.
Network interface adapters: As we mention earlier in this chapter,
home networks use a communication method (protocol) known as
Ethernet. The communication that takes place between the components
of your computer, however, does not use the Ethernet protocol. As a
result, for computers on the network to communicate through the
Ethernet protocol, each of the computers must translate between their
internal communication protocol and Ethernet. The device that handles
this translation is a network interface adapter, and each computer on the
network needs one. Prices for network interface adapters are typically
much less than $50, and most new computers come with one at no additional
cost.
A network interface adapter that installs inside a computer is usually
called a network interface card (NIC). Many computer manufacturers
now include an Ethernet NIC with each personal computer as a standard
feature.
Wireless network interface adapter: To wirelessly connect a computer
to the network, you must obtain a wireless network interface adapter for
each computer. Prices range between $50 and $150. A few portable computers
now even come with a wireless network interface built in. These
are very easy to use; most are adapters that just plug in.
The four most common types of wireless network interface adapters are
• PC Card: This type of adapter is often used in laptop computers
because most laptops have one or two PC Card slots.
CF card: A Compact Flash (CF) card adapter is smaller in size than
a PC Card adapter and enables you to link a Pocket PC or other
palm-sized computer to your network. Many high-end personal digital
assistants (PDAs) now even come with wireless capability
built-in, obviating the need for a wireless adapter.
• USB: A Universal Serial Bus (USB) adapter connects to one of your
computer’s USB ports; these USB ports have been available in
most computers built in the last four or five years.
• ISA or PCI adapter: If your computer doesn’t have a PC Card slot,
CF card slot, or USB port, you have to either install a network interface
card or a USB card (for a USB wireless network interface
adapter) in one of the computer’s internal peripheral expansion
receptacles (slots). The expansion slots in older PCs are Industry
Standard Architecture (ISA) slots. The internal expansion slots in
newer PCs and Apple Macintosh computers follow the Peripheral
Component Interconnect (PCI) standard.

Wireless Standard

IEEE 802.11a: Wireless networks that use the Institute for Electrical and
Electronics Engineers (IEEE) 802.11a standard use the 5 GHz radio frequency
band. Equipment of this type is among the fastest wireless networking
equipment widely available to consumers.
IEEE 802.11b: Home wireless networks that use the IEEE 802.11b standard
use the 2.4 GHz radio band. This is the most popular standard in
terms of numbers of installed networks and numbers of users.
IEEE 802.11g: The last and newest member of the 802.11 wireless family,
IEEE 802.11g is coming to market as this book goes to press. In fact, only
a draft of the IEEE 802.11g specification has been approved with the
finalized specs due by mid-2003. In many ways, 802.11g offers the best of
both worlds — backward compatibility with IEEE 802.11b networks (it,
too, operates over the 2.4 GHz radio frequency band) and the speed of
802.11a networks.
Data speed: IEEE 802.11a and IEEE 802.11g networks are almost ten
times faster than IEEE 802.1b networks. However, IEEE 802.11b networks
are almost ten times faster than the fastest broadband Internet connection.
Unless you expect to routinely share very large files over your network,
you probably wouldn’t be able to notice the difference in speed
between these two standards.
Price: IEEE 802.11a and g networking equipment is typically more expensive
than similar IEEE 802.11b equipment, but the price differential might
be temporary. IEEE 802.11b equipment has been on the market for a
longer period of time than 802.11a and g with dozens of products in the
marketplace. As a result, IEEE 802.11b will probably be the least expensive
version of Wi-Fi for some period of time. However if the first IEEE
802.11g products out the door are any indication, the price differential
between 802.11g and 802.11b will be negligible very soon.
Radio signal range: IEEE 802.11a wireless networks tend to have a
shorter maximum signal range than IEEE 802.11b and g networks. The
actual distances vary depending on the size construction of your home.
In most modern homes, however, all three of the competing standards
should provide adequate range.
Radio signal interference: The radio frequency band used by both IEEE
802.11b and IEEE 802.11g equipment is also used by other home devices,
such as microwave ovens and portable telephones, resulting sometimes
in network problems caused by radio signal interference. Very few other
types of devices currently use the radio frequency band employed by
the IEEE 802.11a standard.
Interoperability: Because IEEE 802.11a and IEEE 802.11b/g use different
frequency bands, they aren’t able to communicate over the same radio.
Several manufacturers, however, have already released products that
can operate with both IEEE 802.11a and IEEE 802.11b/g equipment simultaneously.
By contrast, IEEE 802.11g equipment is designed to be backward
compatible with IEEE 802.11b equipment — both operating on the
same frequency band — but in early tests of the first IEEE 802.11g products,
actual interoperability was often problematic. Nevertheless, it will
only be a matter of time before IEEE 802.11g is fully adopted, and multistandard
(802.11 a/b/g) wireless networking equipment will be the norm.

Wired versus Wireless

Ethernet is the most-often used method of connecting personal computers
together to form a network because it’s fast and its equipment is relatively
inexpensive. In addition, Ethernet can be transmitted over several types of
network cable or sent through the air by using wireless networking equipment.
Many new computers have an Ethernet connection built in, ready for
you to plug in a network cable. The most popular wireless networking equipment
transmits a form of Ethernet.

Installing wired home networks
Even though we’re talking mostly about wireless networks in this book and
how great they are, we’d be misleading you if we told you that wireless was
the only way to go. Wireless and wired homes each have advantages.
Wired homes are
Faster: Wired lines can reach 1000 Mbps in speed, whereas wireless
homes tend to be in the 10 Mbps and soon 100 Mbps range. Both wireless
and wired technologies are getting faster and faster, but wired will
always be ahead.
More reliable: Wireless signals are prone to interference and fluctuations;
wired connections typically are more stable and reliable.
More secure: You don’t have to worry about your signals traveling
through the air and being intercepted by snoopers, like with unsecured
wireless systems.
Economical over the long term: The incremental cost of adding Cat 5e
voice and data cabling and RG-6 coaxial cabling into your house — over
a 30-year mortgage — will be almost nothing each month.
Salable: More and more homebuyers are not only looking for well-wired
homes but are discounting homes without the infrastructure. As good as
wireless is, it is not affixed to the house and is carried with you when
you leave. Most new homes have structure wiring in the walls.
If you’re building a new home or renovating an old one, we absolutely recommend
that you consider running the latest wiring in the walls to each of your
rooms. That doesn’t mean that you won’t have a wireless network in your
home — you will. It just will be different than if you were wholly reliant on
wireless for your networking.
If you choose to use network cable, it should ideally be installed in the walls,
just like electrical and phone wiring. Network jacks (outlets) are installed in
the walls in rooms where you would expect to use a computer. Connecting
your computer to a wired network is just as easy as plugging a phone into a
phone jack

Installing wireless home networks

If you’re networking an existing home or are renting your home, wireless has
fabulous benefits:
Portable: You can take your computing device anywhere in the house
and be on the network. Even if you have a huge house, you can interconnect
wireless access points to have a whole home wireless network.
Flexible: You’re not limited to where a jack is on the wall; you can network
anywhere.
Cost effective: You can start wireless networking for a couple of hundred
dollars. Your wiring contractor can’t do much with that!
Clean: You won’t have to tear down walls or trip over wires when they
come out from underneath the carpeting.
What’s more, there’s really no difference how you use your networked computer,
whether it’s connected to the network by a cable or by a wireless networking
device. Whether you’re sharing files, a printer, your entertainment
system, or the Internet over the network, the procedures are the same on a
wireless network as on a wired network. In fact, you can mix wired and wireless
network equipment on the same network with no change in how you use
a computer on the network.
Time for the fine print. We’d be remiss if we weren’t candid and mention any
potential drawbacks to wireless networks compared with wired networks.
The possible drawbacks fall into four categories:
Data speed: Wireless networking equipment does transmit data at
slower speeds than wired networking equipment. Wired networks are
already networking at gigabit speeds, although the fastest wireless networking
standards (in the best situations) tops out at 54 Mbps.
Some vendors have proprietary extensions that will take the speed higher, but
even these top out at a little more than 100 Mbps in the best scenarios.)
But for almost all the uses that we can think of now, this is plenty fast.
Your Internet connection probably doesn’t exceed a few Mbps in speed,
so your wireless connection should be more than fast enough.
Radio signal range: Wireless signals fade when you move away from the
source. Some homes, especially older homes, might be built from materials
that tend to block the radio signals used by wireless networking
equipment, causing even faster signal degradation. If your home has
plaster walls that contain a wire mesh, the wireless networking equipment’s
radio signal might not reach all points in your home. Most
modern construction, however, uses drywall materials that reduce the
radio signal only slightly. As a result, most homeowners can reach all
points in their home with one centralized wireless access point (also
called a base station) and one wireless device in or attached to each personal
computer. And if you need better coverage, you can just add
another access point — we show you how in Chapter 18.
Radio signal interference: The most common type of wireless networking
technology uses a radio frequency that’s also used by other home
devices, such as microwave ovens and portable telephones. Some home
wireless network users, as a consequence, experience network problems
(the network slows down or the signal is dropped) caused by radio
signal interference.
Security: The radio signal from a wireless network doesn’t stop at the
outside wall of your home. A neighbor or even a total stranger could
access your network from an adjoining property or from the street
unless you implement some type of security technology to prevent
unauthorized access. To prevent unauthorized access, you can safeguard
yourself with security technology that comes standard with the
most popular home wireless networking technology. However, it’s not
bulletproof, and it certainly won’t work if you don’t turn it on. For more
on wireless security
For our money, wireless networks compare favorably with wired networks for
most homeowners who didn’t have network wiring installed when the house
was built.

Abbreviations

μs microseconds
2G second generation (cellular)
3G third generation (cellular)
AC access category
ACK acknowledgement
ADC analog-to-digital converter
ADDBA add block acknowledgement
ADDTS add traffic stream
AGC automatic gain control
AID association identifier
AIFS arbitration inter-frame space
A-MPDU aggregate MAC protocol data unit
A-MSDU aggregate MAC service data unit
AoA angle of arrival
AoD angle of departure
AP access point
APSD automatic power save delivery
A-PSDU aggregate PHY service data unit
AS angular spectrum
ASEL antenna selection
AWGN additive white Gaussian noise
BA block acknowledgement
BAR block acknowledgement request
BCC binary convolution code
BF beamforming
BICM bit interleaved coded modulation
bps bits-per-second
BPSCS coded bits per single carrier for each spatial stream
BPSK binary phase shift keying
BSS basic service set
BSSID BSS identifier
BW bandwidth
CBPS coded bits per symbol
CBPSS coded bits per spatial stream
CBW channel bandwidth
CCA clear channel assessment
CCDF complementary cumulative distribution function
CCK complementary code keying
CFP contention free period
CP contention period
CRC cyclic redundancy code
CS carrier sense
CSD cyclic shift diversity
CSI channel state information
CSMA carrier sense multiple access
CSMA/CA carrier sense multiple access with collision avoidance
CSMA/CD carrier sense multiple access with collision detection
CTS clear to send
CW contention window
DA destination address
DAC digital-to-analog converter
dB decibels
dBc decibels relative to carrier
dBi decibels isotropic relative to an antenna
dBm decibel of measured power referenced to one milliwatt
DBPS data bits per OFDM symbol
dBr dB (relative)
DC direct current
DCF distributed coordination function
DELBA delete block acknowledgement
DIFS DCF inter-frame space
DLS direct link session
DS distribution system
DSL digital subscriber line
DSSS direct sequence spread spectrum
DTIM delivery traffic indication message
DVD digital versatile disc
EDCA enhanced distributed channel access
EIFS extended inter-frame space
ERP enhanced rate PHY
ESS extended service set
ETSI European Telecommunications Standards Institute
EVM error vector magnitude
EWC Enhanced Wireless Consortium
FCC Federal Communications Commission
FCS frame check sequence
FEC forward error correction
FFT fast Fourier transform
FHSS frequency hopped spread spectrum
FS free space
FTP file transfer protocol
GF Greenfield
GF-HT-STF Greenfield High Throughput Short Training field
GHz gigahertz
GI guard interval
GIF graphics interchange format
GPS global positioning system
HC hybrid coordinator
HCCA HCF controlled channel access
HCF hybrid coordination function
HEMM HCCA, EDCA mixed mode
HT high throughput
HTC high throughput control
HT-DATA High Throughput Data field
HT-LTF High Throughput Long Training field
HTSG High Throughput Study Group
HT-SIG High Throughput Signal field
HT-STF High Throughput Short Training field
HTTP hypertext transfer protocol
Hz Hertz
IBSS independent basic service set
IC integrated circuit
IDFT inverse discrete Fourier transform
IEEE Institute of Electrical and Electronic Engineers
IFFT inverse fast Fourier transform
IFS inter-frame space
IP Internet Protocol
IPv6 Internet Protocol version 6
IR infrared
ISI inter-symbol interference
ISM industrial, scientific, and medical
JPEG Joint Photographic Experts Group
kHz kilohertz
km/h kilometers per hour
LAN local area networking
LDPC low density parity check
LLC logical link control
L-LTF Non-HT (Legacy) Long Training field
LNA low noise amplifier
LOS line-of-sight
LSB least significant bit
L-SIG Non-HT (Legacy) Signal field
L-STF Non-HT (Legacy) Short Training field
LTF Long Training field
m meters
MAC medium access control
MAI MRQ or ASEL indication
MAN metropolitan area networking
Mbps megabit per second
MCS modulation and coding scheme
MF mixed format
MFB MCS feedback
MFSI MCS feedback sequence indication
MHz megahertz
MIB management information base
MIMO multiple-input multiple-output
ML maximum likelihood
MMPDU MAC management protocol data unit
MMSE minimum mean-square-error
MPDU MAC protocol data unit
MPEG Moving Picture Experts Group
MRC maximal-ratio combining
MRQ MCS request
Msample/s mega-samples per second
MSB most significant bit
MSDU MAC service data unit
MSE mean-square-error
MSFI MCS feedback sequence identifier
MSI MCS request sequence identifier
NAV network allocation vector
NDP null data packet
NF noise figure
NLOS non-line-of-sight
nsec nanosecond
OBO output back-off
OBSS overlapping BSS
OFDM orthogonal frequency division multiplexing
OSI open systems interconnection
PA power amplifier
PAR project authorization request
PAS power angular spectrum
PC point coordinator
PCF point coordination function
PCO phased coexistence operation
PDU protocol data unit
PER packet error rate
PHY physical layer
PIFS PCF inter-frame space
PLCP physical layer convergence procedure
PPDU PLCP protocol data unit
ppm parts per million
PSD power spectral density
PSDU PLCP service data unit
PSMP power-save multi-poll
PSMP-DTT PSMP downlink transmission time
PSMP-UTT PSMP uplink transmission time
QAM quadrature amplitude modulation
QoS quality of service
QPSK quadrature phase shift keying
R code rate
RA receiver address
RD reverse direction
RDG reverse direction grant
RF radio frequency
RIFS reduced inter-frame space
RMS root-mean-square
RSSI received signal strength indication
RTS request to send
Rx receive
SA source address
SAP service access point
SCP secure copy protocol
SDM spatial division multiplexing
SDU service data unit
SE spatial expansion
SIFS short inter-frame space
SIG Signal field
SIMO single-input, multiple-output
SISO single-input, single-output
SMTP simple mail transfer protocol
SNR signal-to-noise ratio
SOHO small-office, home-office
SS spatial stream
SSC starting sequence control
SSID service set identifier
SSN starting sequence number
STA station
STBC space-time block coding
STF Short Training field
STS space-time stream
SVD singular value decomposition
SYM symbol
TA transmitter address
TBTT target beacon transmission time
TC traffic category
TCLAS traffic classification
TCM trellis coded modulation
TCP transmission control protocol
TDD time division duplexing
TGn Task Group n
TGy Task Group y
TID traffic identifier
TIFF tagged image file format
TRQ training request
TS traffic stream
TSID traffic stream identifier
TSPEC traffic specification
TV television
Tx transmit
TxBF transmit beamforming
TXOP transmit opportunity
TXTIME transmit time
UDP user datagram protocol
USA United States of America
VoIP voice over IP
VPN virtual private network
WEP wired equivalent privacy
WFA Wi-Fi Alliance
WLAN wireless local area network
WM wireless medium
WNG SC Wireless Next Generation Standing Committee
WWiSE world wide spectral efficiency
XOR exclusive-or
ZF zero-forcing
ZIP ZIP file format

Saturday, March 13, 2010

Wireless Protected Access

Differences

WPA is an encryption algorithm that takes care of a lot of the vunerablities inherent in WEP. WEP is, by design, flawed. No matter how good or crappy, long or short, your WEP key is, it can be cracked. WPA is different. A WPA key can be made good enough to make cracking it unfeasible. WPA is also a little more cracker friendly. By capturing the right type of packets, you can do your cracking offline. This means you only have to be near the AP for a matter of seconds to get what you need. Advantages and disadvantages.

WPA Flavours

WPA basically comes in two flavours RADIUS or PSK. PSK is crackable, RADIUS is not so much.

PSK uses a user defined password to initialize the TKIP, temporal key integrity protocol. There is a password and the user is involved, for the most part that means it is flawed. The TKIP is not really crackable as it is a per-packet key but upon the initialization of the TKIP, like during an authentication, we get the password (well the PMK anyways). A robust dictionary attack will take care of a lot of consumer passwords.

Radius involves physical transferring of the key and encrypted channels blah blah blah, look it up to learn more about it but 90% of commerical APs do not support it, it is more of an enterprise solution then a consumer one.

The Handshake

The WPA handshake was designed to occur over insecure channels and in plaintext so the password is not actually sent across. There are some fancy dancy algorithms in the background that turn it into a primary master key, PMK, and the like but none of that really matters cause the PMK is enough to connect to the network.

The only step we need to do is capture a full authenication handshake from a real client and the AP. This can prove tricky without some packet injection, but if you are lucky to capture a full handshake, then you can leave and do the rest of the cracking at home.

We can force an authenication handshake by launching a Deauthentication Attack, but only if there is a real client already connected (you can tell in airodump). If there are no connected clients, you're outta luck.

Like for WEP, we want to know the channel the WPA is sitting on, but the airodump command is slightly different. We don't want just IVs so we don't specify an IV flag. This will produce "lucid.cap" instead of "lucid.ivs". Assume WPA is on channel 6 and wireless interface is ath0.

./airodump ath0 lucid 6


Dictionary Brute Force

The most important part of brute forcing a WPA password is a good dictionary. Check out http://www.openwall.com/wordlists/ for a 'really' good one. It costs money, but its the biggest and best I've ever seen (40 Million words, no duplicates, one .txt file). There is also a free reduced version from the same site but i'm sure resourceful people can figure out where to get a good dictionary from.

When you have a good dictionary the crack is a simple brute force attack:

./aircrack -a 2 -b 00:23:1F:55:04:BC -w /path/to/wordlist

Either you'll get it or you won't... depends on the strength of the password and if a dictionary attack can crack it.

Using Aireplay

Aireplay is the fun part. You get to manipulate packets to trick the network into giving you what you want.

WEP Attacks

Attacks used to create more traffic on WEP networks to get more IVs.

ARP Injection

ARP Replay is a classic way of getting more IV traffic from the AP. It is the turtle. Slow but steady and almost always works. We need the BSSID of the AP and the BSSID of an associated client. If there are no clients connected, it is possible to create one with another WEP attack explained below: Fake Authentication Attack.

With airodump listening, we attack:

./aireplay -3 -b -h ath0

Note: The -3 specifys the type of attack (3=ARP Replay).

This will continue to run, and airodump, listening fron another terminal, will pick up anY reply IVs.

Interactive Packet Replay

Interactive Packet Reply is quite a bit more advanced and requires capturing packets and constructing your own. It can prove more effective then simple ARP requests but I won't get into packet construction here.

A useful attack you might try is the re-send all data attack, basically you are asking the AP to re-send you everything. This only works if the AP re-encrypts the packets before sending them again (and therefore giving you a new IV). Some APs do, some don't.

aireplay -2 -b -h -n 100 -p 0841 -c FF:FF:FF:FF:FF:FF ath0


Fake Authentication Attack

This attack won't generate any more traffic but it does create an associative client MAC Address useful for the above two attacks. Its definately not as good as having a real, connected client, but you gots to do what you gots to do.

This is done easiest with another machine because we need a new MAC address but if you can manually change your MAC then that'll work too. We'll call your new MAC address "Fake MAC".

Now most APs need clients to reassociate every 30 seconds or so or they think they're disconnected. This is pretty arbitrary but I use it and it has worked but if your Fake MAC gets disconnected, reassociate quicker. We need both the essid and bssid and our Fake MAC.

./aireplay -1 30 -e '' -a -h ath0

If successful, you should see something like this:

23:47:29 Sending Authentication Request
23:47:29 Authentication successful
23:47:30 Sending Association Request
23:47:30 Association successful :-)

Awesome! Now you can use the above two attacks even though there were no clients connected in the first place! If it fails, there may be MAC Address Filtering on so if you really want to use this, you'll have to sniff around until a client provides you with a registered MAC to fake.

WPA Attacks

So far, the only way to really crack WPA is to force a re-authentication of a valid client. We need a real, actively connected client to break WPA. You might have to wait a while.

Deauthentication Attack

This is a simple and very effective attack. We just force the connected client to disconnect then we capture the re-connect and authentication, saves time so we don't have to wait for the client to do it themselves (a tad less "waiting outside in the car" creepiness as well). With airodump running in another console, your attack will look something like this:

aireplay -0 5 -a -c ath0

After a few seconds the re-authentication should be complete and we can attempt to Dictionary Brute Force the PMK.

Conclusion

Well thats that. APs crack fairly often but sometimes there is just nothing you can do. Obviously you are not allowed to illegally crack other people's wireless connections, this is purely for penetration testing purposes and some fun.
 
[URL=http://s06.flagcounter.com/more/6xL][IMG]http://s06.flagcounter.com/count/6xL/bg=FFFFFF/txt=000000/border=CCCCCC/columns=3/maxflags=20/viewers=0/labels=0/[/IMG][/URL] Locations of visitors to this page