maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Applications (https://talk.maemo.org/forumdisplay.php?f=41)
-   -   rt73 + aireplay-ng = packet injection (https://talk.maemo.org/showthread.php?t=13458)

Benson 2008-09-06 16:30

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by bigjoejack (Post 221443)
Hi I have the Alpha Network AWSUS036H but can't get aireplay to work on Ubuntu 8.04. I had this working with Fedora Core 6 a while back with the patch from aircrack-ng. I installed Ubuntu yesterday and followed the same steps but couldn't get it to work.

When I run:
sudo aireplay-ng -1 0 -e bigjoejack -a 00:1C:10:1B:0E:C1 -h 00:c0:ca:19:cd:48 wlan1

it tells me that the attack was unsuccessful.

Linux pcuser-laptop 2.6.24-19-generic #1 SMP Wed Aug 20 22:56:21 UTC 2008 i686 GNU/Linux

Patched it following the link below:
http://www.aircrack-ng.org/doku.php?id=r8187

Patch was applied successfully....

I followed these steps for the cracking:
http://s32.photobucket.com/player.sw...fs=1&os=1&ap=1

Why can I get this going in FC but not Ubuntu?

I'm in the process of download the BT3 ISO but would prefer using Ubuntu.

Thanks for reading and hope I hear back from someone soon.

Later,

BigJoeJack

I think you're on the wrong forum; internettablettalk is mainly about Nokia internet tablets, the 770, N800, and N810. ;)

custode 2008-09-15 18:16

Re: rt73 + aireplay-ng = packet injection
 
I am absolutely new to this area, but I noticed an item I wanted to run past those of you with more knowledge of the topic. The Immunity SILICA product is on the N770 or N800 depending on what you read, and seems to have some ability to breach networks. I'm not certain that this includes cracking wep/wpa, but would assume so, since they tout the usability of it. Anyway, my general question is:

It seems they have packet injection on the N770, and never mention any external adaptor. Does anyone have any more information or ideas on how that may have been done?

And, as a follow-on...is it POSSIBLE (assuming precision skills) to swap out a chipset? Are they somewhat uniform in power consumption, physical parameters, etc? Or would a unit require many other mods to accomodate?

Thanks so much.

jaeezzy 2008-09-19 13:17

Re: rt73 + aireplay-ng = packet injection
 
Hi, I got DLink DWA-110, will I be able to use this? has anybody tried with this? if so let me know.. thanks

murphy 2008-09-23 10:35

Re: rt73 + aireplay-ng = packet injection
 
Since the integrated wlan driver just became opensourced, is it now possible to use paquet injection with n800/810 ?

Benson 2008-09-23 10:46

Re: rt73 + aireplay-ng = packet injection
 
No, because that's not what happened. It's a new driver and it's still alpha. (Even if it was the existing driver open-sourced, someone would still need to write an injection patch...)

mike2k4 2008-10-03 04:02

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mike2k4 (Post 216903)
I cant seem to get my Belkin F5D7050 working yet. After I follow the steps and load the RT73.ko, my n800 would get segmentation faults if I try to us iwconfig, ifconfig or even sudo gainroot in another terminal. Sometimes it would just restart as well. Here is a dmesg before it decided to restart.

Code:

[  19.000000] hub 1-0:1.0: power on to power good time: 10ms
[  19.000000] hub 1-0:1.0: 200mA bus power budget for each child
[  19.000000] hub 1-0:1.0: local power source is good
[  19.000000] hub 1-0:1.0: enabling power on all ports
[  19.000000] drivers/usb/musb/tusb6010.c musb_platform_enable: dma not reactivated
[  19.109375] drivers/usb/core/inode.c: creating file '001'
[  19.109375] hub 1-0:1.0: state 7 ports 1 chg 0000 evt 0000
[  20.804687] EAC mode: play disabled, rec disabled
[  21.109375] hub 1-0:1.0: hub_suspend
[  21.109375] usb usb1: usb auto-suspend
[  24.046875] EAC mode: play enabled, rec enabled
[  31.648437] EAC mode: play disabled, rec disabled
[  37.539062] Adding 131064k swap on /media/mmc2/.swap.  Priority:-1 extents:1 across:131064k
[  42.671875] cx3110x: loading 3826.arm firmware.
[  42.929687] (c)opyright 2004 Conexant
[  42.929687]
[  42.929687] build info: PRISM SoftMAC
[  42.929687]  creator: [kvalo]
[  42.929687]  date: [07/10/05-11:45]
[  42.929687]
[  42.937500] cx3110x: MAC address 00:19:4f:d5:5e:56.
[  42.945312] cx3110x: libumac version 2.12.0.0.a.9.15-5
[  42.945312] cx3110x: lmac version 2.13.0.0.a.22.8
[  42.945312] cx3110x: PSM disabled.
[  44.796875] cx3110x: scanned 11 channels.
[  45.078125] cx3110x: shut down softmac.
[  45.546875] cx3110x: loading 3826.arm firmware.
[  45.804687] (c)opyright 2004 Conexant
[  45.804687]
[  45.804687] build info: PRISM SoftMAC
[  45.804687]  creator: [kvalo]
[  45.804687]  date: [07/10/05-11:45]
[  45.804687]
[  45.812500] cx3110x: MAC address 00:19:4f:d5:5e:56.
[  45.820312] cx3110x: libumac version 2.12.0.0.a.9.15-5
[  45.820312] cx3110x: lmac version 2.13.0.0.a.22.8
[  47.671875] cx3110x: scanned 11 channels.
[  49.898437] cx3110x: associated to 00:13:46:a5:47:da (bcn 100 msec, DTIM 1).
[  52.546875] cx3110x: PSM dynamic with 200 ms CAM timeout.
[  65.914062] JFFS2 notice: (402) check_node_data: wrong data CRC in data node at 0x0982b4b8: read 0xe061b648, calculated 0xc82d4081.
[  75.601562] JFFS2 notice: (402) check_node_data: wrong data CRC in data node at 0x09346764: read 0x13b525eb, calculated 0xaaeff032.
[  77.242187] JFFS2 notice: (402) check_node_data: wrong data CRC in data node at 0x0cd84bac: read 0xc637ee2c, calculated 0xbdd5c5e4.
[  78.484375] JFFS2 notice: (402) check_node_data: wrong data CRC in data node at 0x0eda6c78: read 0xebd8cca3, calculated 0x539ba63f.
[  78.554687] JFFS2 notice: (402) check_node_data: wrong data CRC in data node at 0x0a0e16d8: read 0xdd9e52f3, calculated 0x131d3113.
[  92.320312] DSP Pausing failed, skipping OP change!
[  142.039062] tusb_source_power 629: VBUS a_wait_vrise, devctl 81 otg 184 conf c0010001 prcm 00a80500
[  146.250000] cx3110x: PSM dynamic with 100 ms CAM timeout.
[  421.703125] EAC mode: play enabled, rec enabled
[  422.046875] cx3110x: PSM dynamic with 200 ms CAM timeout.
[  424.203125] EAC mode: play disabled, rec disabled
[  502.773437] musb_stage0_irq 570: VBUS_ERROR in a_wait_bcon (91, <VBusValid), retry #1, port1 00000100
[  513.710937] EAC mode: play enabled, rec enabled
[  516.210937] EAC mode: play disabled, rec disabled
[  537.460937] musb_stage0_irq 570: VBUS_ERROR in a_wait_bcon (91, <VBusValid), retry #2, port1 00000100
[  558.281250] tusb_source_power 629: VBUS a_wait_vrise, devctl 91 otg 15c conf c0010000 prcm 00a80500
[  558.375000] tusb_otg_ints 833: vbus too slow, devctl 81
[  558.375000] tusb_source_power 629: VBUS b_idle, devctl 80 otg 188 conf c0000000 prcm 00a80500
[  560.976562] musb_stage2_irq 817: SUSPEND (b_idle) devctl 91 power e0
[  562.835937] tusb_source_power 629: VBUS a_wait_vrise, devctl 91 otg 151 conf c0010000 prcm 00a80500
[  562.929687] tusb_otg_ints 833: vbus too slow, devctl 91
[  562.929687] tusb_source_power 629: VBUS a_wait_vfall, devctl 90 otg 151 conf c0000000 prcm 00a80500
[  563.804687] tusb_source_power 629: VBUS a_idle, devctl 90 otg 154 conf c0000000 prcm 00a80300
[  563.812500] tusb_source_power 629: VBUS a_idle, devctl 90 otg 154 conf c0000000 prcm 00a80300
[  570.984375] tusb_source_power 629: VBUS a_wait_vrise, devctl 91 otg 154 conf c0010001 prcm 00a80300
[  571.156250] musb_stage0_irq 646: CONNECT (a_host) devctl 5d
[  571.156250] hub 1-0:1.0: state 8 ports 1 chg 0000 evt 0000
[  571.156250] usb usb1: usb auto-resume
[  571.156250] usb usb1: finish resume
[  571.156250] hub 1-0:1.0: hub_resume
[  571.179687] hub 1-0:1.0: port 1, status 0101, change 0001, 12 Mb/s
[  571.335937] hub 1-0:1.0: debounce: port 1: total 100ms stable 100ms status 0x101
[  571.460937] usb 1-1: new high speed USB device using musb_hdrc and address 2
[  571.593750] usb 1-1: default language 0x0409
[  571.593750] usb 1-1: new device strings: Mfr=1, Product=2, SerialNumber=0
[  571.593750] usb 1-1: Product: USB2.0 Hub Controller
[  571.593750] usb 1-1: Manufacturer: NEC Corporation
[  571.593750] usb 1-1: hub v0409 p0058 is not supported
[  571.593750] usb 1-1: uevent
[  571.593750] usb 1-1: usb_probe_device
[  571.593750] usb 1-1: configuration #1 chosen from 1 choice
[  571.593750] usb 1-1: adding 1-1:1.0 (config #1, interface 0)
[  571.593750] usb 1-1:1.0: uevent
[  571.593750] hub 1-1:1.0: usb_probe_interface
[  571.593750] hub 1-1:1.0: usb_probe_interface - got id
[  571.593750] hub 1-1:1.0: USB hub found
[  571.593750] hub 1-1:1.0: 4 ports detected
[  571.593750] hub 1-1:1.0: standalone hub
[  571.593750] hub 1-1:1.0: individual port power switching
[  571.593750] hub 1-1:1.0: individual port over-current protection
[  571.593750] hub 1-1:1.0: Single TT
[  571.593750] hub 1-1:1.0: TT requires at most 16 FS bit times (1332 ns)
[  571.593750] hub 1-1:1.0: Port indicators are supported
[  571.593750] hub 1-1:1.0: power on to power good time: 100ms
[  571.601562] hub 1-1:1.0: local power source is good
[  571.601562] hub 1-1:1.0: enabling power on all ports
[  571.710937] drivers/usb/core/inode.c: creating file '002'
[  571.710937] hub 1-0:1.0: 100mA power budget left
[  571.710937] hub 1-0:1.0: state 7 ports 1 chg 0000 evt 0002
[  571.710937] hub 1-0:1.0: port 1 enable change, status 00000503
[  571.710937] hub 1-1:1.0: state 7 ports 4 chg 0000 evt 0002
[  571.710937] hub 1-1:1.0: port 1, status 0101, change 0001, 12 Mb/s
[  571.867187] hub 1-1:1.0: debounce: port 1: total 100ms stable 100ms status 0x101
[  571.953125] usb 1-1.1: new high speed USB device using musb_hdrc and address 3
[  572.085937] usb 1-1.1: new device strings: Mfr=0, Product=0, SerialNumber=0
[  572.085937] usb 1-1.1: hub v050d p7050 is not supported
[  572.085937] usb 1-1.1: uevent
[  572.085937] usb 1-1.1: usb_probe_device
[  572.085937] usb 1-1.1: configuration #1 chosen from 1 choice
[  572.085937] usb 1-1.1: adding 1-1.1:1.0 (config #1, interface 0)
[  572.085937] usb 1-1.1:1.0: uevent
[  572.085937] usbtest 1-1.1:1.0: usb_probe_interface
[  572.085937] usbtest 1-1.1:1.0: usb_probe_interface - got id
[  572.085937] drivers/usb/core/inode.c: creating file '003'
[  574.085937] usb 1-1.1: usb auto-suspend
[  576.109375] hub 1-1:1.0: hub_suspend
[  576.109375] usb 1-1: usb auto-suspend
[  578.132812] hub 1-0:1.0: hub_suspend
[  578.132812] usb usb1: usb auto-suspend
[  586.843750] EAC mode: play enabled, rec enabled
[  591.054687] EAC mode: play disabled, rec disabled
[  703.140625] rtusb init ====>
[  703.140625] rt73 1-1.1:1.0: usb_probe_interface
[  703.140625] rt73 1-1.1:1.0: usb_probe_interface - got id
[  703.140625] usb usb1: usb auto-resume
[  703.140625] usb usb1: finish resume
[  703.140625] hub 1-0:1.0: hub_resume
[  703.164062] usb 1-1: usb auto-resume
[  703.164062] hub 1-0:1.0: state 7 ports 1 chg 0000 evt 0000
[  703.265625] hub 1-0:1.0: state 7 ports 1 chg 0000 evt 0002
[  703.304687] usb 1-1: finish resume
[  703.304687] hub 1-1:1.0: hub_resume
[  703.304687] hub 1-1:1.0: state 7 ports 4 chg 0000 evt 0000
[  703.304687] usb 1-1.1: usb auto-resume
[  703.367187] usb 1-1.1: finish resume
[  703.367187] idVendor = 0x50d, idProduct = 0x7050
[  703.445312] rt73: Firmware loading error
[  703.445312] rt73: probe of 1-1.1:1.0 failed with error -32
[  703.445312] usbcore: registered new interface driver rt73
[  705.445312] usb 1-1.1: usb auto-suspend
Nokia-N800-23-14:~#

Anyone else have this issue? I am using a powered usbhub.

Any ideas? Should I try to compile it myself?

jaeezzy 2008-10-08 03:52

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mutex (Post 112422)
Edimax 7318USg, really cheap and has an external rp-sma antenna connector.
http://www.edimax.com/en/produce_det...id=1&pl2_id=44

Hi, I've just bought the same adapter and I tried the steps in the beginning of the page but when i hit iwconfig i get this:

/home/user/MyDocs/.documents/test # iwconfig
lo no wireless extensions.

wlan0 NOT READY ESSID:off/any
Mode:Auto Channel:0 Access Point: Not-Associated
Link Quality:0 Signal level:0 Noise level:0
Rx invalid nwid:0 invalid crypt:0 invalid misc:0

/home/user/MyDocs/.documents/test #

What do I have to do? thanks....

kyokorn 2008-10-17 20:25

Re: rt73 + aireplay-ng = packet injection
 
Great work

I have a question for you

What firmware have in your n800 ?

BR

solca 2008-10-17 22:29

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by Benson (Post 226505)
No, because that's not what happened. It's a new driver and it's still alpha. (Even if it was the existing driver open-sourced, someone would still need to write an injection patch...)

Wrong; software MAC radios with drivers written for mac80211 supports injection. It just seems that nobody has tested the new driver.

If someone could just pack a kernel with mac80211 and the new driver for us...

jaeezzy 2008-10-27 07:29

Re: rt73 + aireplay-ng = packet injection
 
hi, I'm newbie and luckily I could successfully do 'iwpriv wlan1 rfmontx 1' and then test with 'iwpriv wlan1 get_rfmontx' after doing 'ifconfig wlan1 up' but no matter how many times I try and despite moving around I keep getting this when checking injection with aireplay-ng './aireplay-ng wlan1 --test':

/home/user/MyDocs/.documents/test # ./aireplay-ng wlan1 --test
18:07:25 Trying broadcast probe requests...
18:07:26 No Answer...
18:07:26 Found 0 APs
/home/user/MyDocs/.documents/test #

Though there are lot of access points visible in my laptop in wireless connections.
I tried /sbin/ifconfig wlan1 and got the following:

/home/user/MyDocs/.documents/test # /sbin/ifconfig wlan1wlan1
Link encap:UNSPEC HWaddr 00-1F-1F-12-01-4A-44-EC-00-00-00-00-00-00-00-00
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:276 errors:0 dropped:0 overruns:0 frame:0 TX packets:1 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000
RX bytes:27008 (26.3 KiB) TX bytes:66 (66.0 B)

I don't know if its necessary to provide this detail or not, but still hoping it will give more details on what problem I'm facing. So, is there anything wrong or is it that I have to (as mentioned in the step by step guide by mutex) keep trying moving around (which in fact I did).
By the way I'm using edimax ew-7318usg and I'ven't done any extra thing other than the ones mentioned by mutex (Thanks mutex for your effort and the guide, I'm so impatience to see it do what its supposed to do..).
Thanks..

*EDITED:

Oh!! due to my nube in this thing its kinda irritating, my apology!! I resolved it as I had to change it to monitor mode with : "iwconfig wlan1 mode monitor".

I QUESTION THOUGH: when I tried to run the "./aircrack-ng -b <mac addr> dumpfile*.cap" it says: Please specify a dictionary (option -w). So, when I went to the manpage it was written: specify "-" to use stdin. So, should I type: "./aircrack-ng - -b <mac addr> dumpfile*.cap" ??? Thank you.

mike2k4 2008-11-03 06:47

Re: rt73 + aireplay-ng = packet injection
 
I switched to a edimax ew-7318usg and no longer get the errors and crashing i was getting before, but now I get the no response, Found 0 APs as jaeezzy does.

If I use "iwconfig wlan1 mode monitor" I get the same results,

However If I use "airmon-ng start wlan1", t atleast finds the APs but is unable to inject. What is the difference between using iwconfig and airmon-ng to put the card into monitor mode?

jaeezzy 2008-11-04 11:09

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mike2k4 (Post 238937)
I switched to a edimax ew-7318usg and no longer get the errors and crashing i was getting before, but now I get the no response, Found 0 APs as jaeezzy does.

If I use "iwconfig wlan1 mode monitor" I get the same results,

However If I use "airmon-ng start wlan1", t atleast finds the APs but is unable to inject. What is the difference between using iwconfig and airmon-ng to put the card into monitor mode?

Unplugging and plugging back, changing to otg and back to host mode back again and even restarting my IT do the work for me coz still sometime I get "No Answer" message. Everything is working now even cracked both WEP and WPA2 passphrases.

mike2k4 2008-11-19 05:01

Re: rt73 + aireplay-ng = packet injection
 
Thanks Jaeezzy, I didnt realize that it still works if you sometimes get that message.

XTC 2008-12-14 11:28

Re: rt73 + aireplay-ng = packet injection
 
Can anyone compile driver for other than rt73 chipset?
For example Realtek 8187.
rt73 chipset is quite old and relatively hard to find.
Could somebody help with this specific driver? This driver is in back-track's3 kernel by default.

qwerty12 2008-12-14 11:31

Re: rt73 + aireplay-ng = packet injection
 
http://www.internettablettalk.com/fo...ad.php?t=19575 - but people say that the diablo ones I compiled aren't working, I don't have a 8187 so I don't know...

mrgreaper 2008-12-15 18:52

Re: rt73 + aireplay-ng = packet injection
 
im confused, what does this do?

mrgreaper 2008-12-16 00:23

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by jaeezzy (Post 239229)
Unplugging and plugging back, changing to otg and back to host mode back again and even restarting my IT do the work for me coz still sometime I get "No Answer" message. Everything is working now even cracked both WEP and WPA2 passphrases.

just realised what this is, now reportinng it to the mods and when i find where i report it to the relevent legal organisations 7 months ago i hit a invisible limit, wierd i thought, then 6 months i went over again and got charged,i checked my router and discovered an extra ip i then changed my wep code assuming the default had been guesed it reappeared a week later so i disabled wi fi, for 2 months maybe more, i guess it was prats like the topic creator that allowed this scum to steal my wifi with this type of software. now this may seem harsh, im sure theres legit reasons to hack wifi cant think of any my self, but im sure this should NEVER be publicly available

D'ohboy 2008-12-16 04:59

Re: rt73 + aireplay-ng = packet injection
 
Well mrgreaper I would say that this software is a tool. Like any tool there are bad uses and good uses for it. There are bad uses like stealing wi-fi and there are good uses like security testing. For example you could run it against networks you have permission to use it on, such as your own, to test the security of your own network. So if someone runs it they might learn some things like, I should really change the default password, I should change the password to a strong password, or I don't really need wi-fi on, or I should really use WPA2 instead of the really, really. really, really, easily cracked WEP. Finally, security through obscurity does not work, if it did Windows would be the most secure OS out there. The presence of these tools, if anything, increases security by making the flaws in WEP something that router and wireless card manufactures cannot ignore. Really, finally, if you use WPA2 and a long non-dictionary password with some special characters you can make it almost impossible for someone to crack your network.

Thesandlord 2008-12-16 05:19

Re: rt73 + aireplay-ng = packet injection
 
mrgreaper, I am really sorry for you. Anyone who abuses this technology is really bad. There are only two usage scenario's I can see, one is testing your own set-up, and the other is cracking someone's internet if you really need it (aka you are completely lost, no cell signal, its getting dark, etc). I think this is ok, but overcharging you like that is really a crime. I don't think people here are interested in doing those criminal activities. If they really wanted to, they would use a much simpler laptop with Linux, not a tablet.

Also, I would advise you to listen to D'ohboy. I would also add a few notes. Turn OFF your router for added security. It takes like 5 seconds to turn it of and back on. Use WPA2 or whatever the newest security is. Use a 128 bit (or higher) password, made from RANDOM letters and numbers and symbols. There are generators on the internet for this. Seriously, the best thing you can do for these problems is turn your router off. You can't connect to a off router! Next, change you password every month. Its worth it, because most devices remember the password, so you only have to updated them once a month.

If you are a 1337 haxor, chances are the person leaching off your WiFi is some *****, so you can attack him back. :)

Don't blame the technology. If this was not public, then it would be even worse. Manufactures would think everything is fine and dandy, while the underground stoles the interweb.

qwerty12 2008-12-16 16:39

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by Thesandlord (Post 249832)
If you are a 1337 haxor, chances are the person leaching off your WiFi is some *****, so you can attack him back. :)

Oh, for sure:

http://www.ex-parrot.com/~pete/upside-down-ternet.html

I'd use that script to redirect the guy to goatse personally...

mrgreaper 2008-12-16 18:56

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by qwerty12 (Post 249931)
Oh, for sure:

http://www.ex-parrot.com/~pete/upside-down-ternet.html

I'd use that script to redirect the guy to goatse personally...


nice,

cant turn my router off as my server pc would then lose netconnection and i use that to monitier my home while at work :(

if it was a stormy night and youu had a dead car and a dead phone i'd like to think you'd knock on a door before illegaly hacking someones wifi!

i reported this to the mods but couldnt find who to report it to officialy though i have emailed the C I B (citezens advice beuru) they should be able to advise me where to report this to.you serously believe everyone here just wants to check there wifi security?

qole 2008-12-16 21:58

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mrgreaper (Post 249969)
you serously believe everyone here just wants to check there wifi security?

I do.

Quote:

Originally Posted by D'ohboy (Post 249829)
Finally, security through obscurity does not work, if it did Windows would be the most secure OS out there.

Huh? What?

Rassilon7 2008-12-16 22:09

Re: rt73 + aireplay-ng = packet injection
 
I've used programs like this to test my security too.

D'ohboy 2008-12-16 23:10

Re: rt73 + aireplay-ng = packet injection
 
I was making a crack at Windows, because they support security through obscurity. To quote Windows v Linux security: the real facts.
Quote:

Myth Open Source Software is inherently dangerous because its source code is widely available, whereas Windows 'blueprints' are carefully guarded by Microsoft.
Fact This 'inherent danger' clearly has not manifested itself in terms of actual attacks. Windows-specific viruses, Trojans, worms and malicious programs exist in huge numbers, so if one gives any credence at all to this claim, one would do better to phrase it 'Open Source Software ought to be more dangerous'. But the claim itself hinges on the view - rejected by reputable security professionals - that obscurity aids security. Obscurity/secrecy can also make it more difficult for the vendors themselves to identify vulnerabilities in their own products, and can lead to security issues being neglected because they are not widely-known. The Open Source model, on the other hand, facilitates widespread review and makes it easier to identify and correct flaws. Modular design principles support this, while the overall approach is far more in line with security industry thinking than is 'security through obscurity.'
In addition good security practices like using WPA2, a strong password, and changing that password periodically are just good habits to have. Also I would liken this software to any other tool like for example torrent software, it can be used to pirate films and TV shows, but I have used torrents to download Ubuntu Linux ISOs. Software is just software it is how someone uses it that makes it bad or good.

Aisu 2008-12-16 23:59

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mrgreaper (Post 249969)
if it was a stormy night and youu had a dead car and a dead phone i'd like to think you'd knock on a door before illegaly hacking someones wifi!

Depends on the part of town I'm driving through...

Quote:

i reported this to the mods but couldnt find who to report it to officialy though i have emailed the C I B (citezens advice beuru) they should be able to advise me where to report this to.you serously believe everyone here just wants to check there wifi security?
Are... are you kidding? None of this is illegal. You're threatening to report a bunch of geeks (who mostly live outside your country) with reporting them to... someone.

I use this software for security testing on several networks, mon amie.

Where are the grammar nazis when you need them, anyway? ;)

/shrugs

qole 2008-12-17 00:47

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by D'ohboy (Post 250037)
I was making a crack at Windows, because they support security through obscurity.

I didn't understand your comment because most of the (non-embedded) computers in the world run Windows, and the Windows API is designed for a great deal of backwards-compatibility; there's very little obscure about Windows at all. :D

D'ohboy 2008-12-17 02:07

Re: rt73 + aireplay-ng = packet injection
 
Heh, I guess I should have made a distinction between the obscure of "Man this weeks Robot Chicken referenced a lot of obscure 80's cartoons" and obscure of "The curtain obscured the man behind the curtain."

I also wonder if setting your router to hand out only a limited number of IP addresses would help security.

qole 2008-12-17 05:20

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by D'ohboy (Post 250090)
Heh, I guess I should have made a distinction between the obscure of "Man this weeks Robot Chicken referenced a lot of obscure 80's cartoons" and obscure of "The curtain obscured the man behind the curtain."

Who is Robot Chicken? ;)

And Bill Gates might be standing behind the curtain, but I can see his shoes.

Quote:

Originally Posted by D'ohboy (Post 250090)
I also wonder if setting your router to hand out only a limited number of IP addresses would help security.

WPA with a strong password is fine. Unless you're a bank or something.

odius 2008-12-22 06:35

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by luca (Post 112312)
But since the relevant part of the driver is closed source it's impossible to modify, so the only way is using an external adapter.

closed source meaning they legally wont let u modify it if one can get their hands on it?

.. must be someone with spare time and skills to rewrite the internal NIC driver

I'll throw at least $40 in for whoever does it

odius 2008-12-22 08:04

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by Benson (Post 226505)
..It's a new driver and it's still alpha. (Even if it was the existing driver open-sourced, someone would still need to write an injection patch...)

you can guess what's on my xmas wishlist!

LaVorAta 2008-12-29 19:22

Re: rt73 + aireplay-ng = packet injection
 
Can someone help me out? I have a usb WiFI adapter with a RT8187 chipset. Do I need to compile the drivers for my 770 myself, or are there already some around somewhere?

anest 2009-01-18 10:33

Re: rt73 + aireplay-ng = packet injection
 
someone compiled r8187/rtl8187 already? just still waiting for...

bleomycin 2009-02-28 11:26

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by mrgreaper (Post 249969)
nice,
i have emailed the C I B (citezens advice beuru) they should be able to advise me where to report this to.you serously believe everyone here just wants to check there wifi security?

BAHAHAHAHAHA

i'm sorry, it must be something in the water because people seem to getting more insane every day. Watch FOX news much? :eek:

b0rka7a 2009-03-12 18:07

Re: rt73 + aireplay-ng = packet injection
 
I need help. I just can't get it to work on my N800... I have an Edimax EW-7318Ug.

I'm stuck at loading the driver. When I enter "insmod ./rt732.ko" the command line freezes. Output from dmesg:
Code:

[ 3964.796875] usb 1-1: khubd timed out on ep0in len=0/64
[ 3965.796875] usb 1-1: khubd timed out on ep0in len=0/64
[ 3966.796875] usb 1-1: khubd timed out on ep0in len=0/64
[ 3966.906250] usb 1-1: device descriptor read/64, error -110
[ 3972.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 3977.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 3982.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 3982.125000] usb 1-1: device descriptor read/64, error -110
[ 3982.234375] musb_stage0_irq 569: VBUS_ERROR in a_host (91, <VBusValid), retry #1, port1 00030111
[ 3982.296875] hub 1-0:1.0: port_wait_reset: err = -22
[ 3982.296875] hub 1-0:1.0: port 1 not enabled, trying reset again...
[ 3982.421875] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 3982.507812] hub 1-0:1.0: port_wait_reset: err = -22
[ 3982.507812] hub 1-0:1.0: port 1 not enabled, trying reset again...
[ 3982.507812] musb_stage0_irq 569: VBUS_ERROR in a_host (91, <VBusValid), retry #1, port1 00130111
[ 3982.695312] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 3982.718750] hub 1-0:1.0: port_wait_reset: err = -22
[ 3982.718750] hub 1-0:1.0: port 1 not enabled, trying reset again...
[ 3982.718750] musb_stage0_irq 569: VBUS_ERROR in a_host (91, <VBusValid), retry #1, port1 00130111

Output from lsmod:
Code:

# lsmod | grep rt73
rt73 312624 1 - Loading 0xbf098000
#

I can't kill the insmod proccess even with the -9 switch. I have to unplug the adapter.

After plugging it back in lsmod says:
Code:

# lsmod | grep rt73
rt73 312484 0 - Live 0xbf098000
#

and dmesg output is:
Code:

[ 6307.531250] musb_stage0_irq 569: VBUS_ERROR in a_wait_bcon (91, <VBusValid), retry #1, port1 00000100
[ 6307.710937] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 6307.710937] hub 1-0:1.0: state 8 ports 1 chg 0000 evt 0000
[ 6307.710937] usb usb1: usb auto-resume
[ 6307.710937] usb usb1: finish resume
[ 6307.710937] hub 1-0:1.0: hub_resume
[ 6307.734375] hub 1-0:1.0: port 1, status 0101, change 0001, 12 Mb/s
[ 6307.890625] hub 1-0:1.0: debounce: port 1: total 100ms stable 100ms status 0x101
[ 6307.890625] musb_stage0_irq 569: VBUS_ERROR in a_host (91, <VBusValid), retry #2, port1 00000111
[ 6308.015625] usb 1-1: new high speed USB device using musb_hdrc and address 48
[ 6308.085937] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 6308.453125] cx3110x: PSM dynamic with 200 ms CAM timeout.
[ 6309.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 6310.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 6311.015625] usb 1-1: khubd timed out on ep0in len=0/64
[ 6311.125000] usb 1-1: device descriptor read/64, error -110

It seems that the driver is not loaded, though... iwconfig only shows lo and wlan0:
Code:

# iwconfig
lo        no wireless extensions.

wlan0    IEEE 802.11b/g  ESSID:"TP-LINK" 
          Mode:Managed  Frequency:2.437 GHz  Access Point: 00:1D:0F:E5:58:DC 
          Bit Rate=54 Mb/s  Tx-Power=19 dBm  Sensitivity=0/200 
          RTS thr:off  Fragment thr:off
          Encryption key:3132-3334-3536-3738-3930-3132-33  Security mode:restricted
          Power Management:on
          Link Quality=65/0  Signal level=-29 dBm  Noise level=-94 dBm
          Rx invalid nwid:0  Rx invalid crypt:0  Rx invalid frag:0
          Tx excessive retries:0  Invalid misc:0  Missed beacon:0

Can anyone help me? Can you recommend me another adapter?
Thanks!

b0rka7a 2009-03-19 15:55

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by b0rka7a (Post 271185)
Can anyone help me? Can you recommend me another adapter?

I don't have that adapter anymore... Please, recommend me another one, that's tested with the N800 and is 100% working.

Thanks!

jcwilk 2009-05-18 06:11

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by b0rka7a (Post 271185)
Can anyone help me? Can you recommend me another adapter? Thanks!

I'm getting the -exact- error messages you are, to the letter.

Code:

[ 4805.835937] hub 1-0:1.0: port_wait_reset: err = -22
[ 4805.835937] hub 1-0:1.0: port 1 not enabled, trying reset again...
[ 4805.835937] hub 1-0:1.0: Cannot enable port 1.  Maybe the USB cable is bad?
[ 4805.835937] hub 1-0:1.0: state 7 ports 1 chg 0000 evt 0002
[ 4805.835937] hub 1-0:1.0: reset change on port 1
[ 4805.835937] hub 1-0:1.0: port 1, status 0101, change 0013, 12 Mb/s
[ 4805.835937] EAC mode: play disabled, rec disabled
[ 4805.859375] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 4806.031250] hub 1-0:1.0: debounce: port 1: total 125ms stable 100ms status 0x101
[ 4806.031250] musb_stage0_irq 569: VBUS_ERROR in a_host (91, <VBusValid), retry #1, port1 00000111
[ 4806.156250] usb 1-1: new high speed USB device using musb_hdrc and address 96
[ 4806.265625] musb_stage0_irq 645: CONNECT (a_host) devctl 5d
[ 4807.156250] usb 1-1: khubd timed out on ep0in len=0/64
[ 4808.156250] usb 1-1: khubd timed out on ep0in len=0/64
[ 4809.156250] usb 1-1: khubd timed out on ep0in len=0/64
[ 4809.265625] usb 1-1: device descriptor read/64, error -110

And just to check I followed the same steps you did to debug it and I got all of the exact same results, I'd like to clarify though that the lsmod changes it to "Live" after the devices is removed, not when it's plugged back in... Also that if you insmod while the device is -not- plugged in, it doesn't hang, and drops the driver into the "Live" status immediately. Seems like it gets stuck on something only while the device is plugged in, but regardless, the device never works.

I'm currently not using a self powered USB hub, so that very well be the cause... Seems consistent that those weird timeout errors could be due to lack of power. I'm going to get a self powered hub in the next few days so i'll report back about whether or not it was the problem.

For the record I'm using a linksys WUSB54GC which I purchased from target about 6 months ago and can inject with successfully in ubuntu using this patch. I'm running on diablo on my N810, and am using a hacked usb cable for host mode (though I also tried dumping in 'host' to no additional effect).

jcwilk 2009-05-23 06:13

Re: rt73 + aireplay-ng = packet injection
 
Quote:

Originally Posted by jcwilk (Post 288299)
I'm going to get a self powered hub in the next few days so i'll report back about whether or not it was the problem.

I got a battery pack hooked up to a self powered hub (portable w00t) and now it works perfectly... I had some issues at first but after reloading the driver and fiddling with it, the original instructions by mutex seem to work...

Except that I can't seem to get injection working... Testing with aireplay yields:

Code:

root@Noki test # ./aireplay-ng -9 wlan1
23:01:06  Trying broadcast probe requests...
23:01:07  No Answer...
23:01:07  Found 1 AP

23:01:07  Trying directed probe requests...
23:01:07  XX:XX:XX:XX:XX:XX - channel: 6 - 'wifinetwork'
23:01:17  0/30: 0%

And doing using aireplay's replay attack doesn't seem to be affecting the data count. I caught many packets passively though, so that seems to work fine, but then when I tried running aircrack I ran into more problems...

No matter what I did after capturing about 140k IVs I couldn't coerce the key out of it, using PTW, -z, regular aircrack-ng, nothing. Could be due to the older version of aircrack? I transferred the cap file over to my desktop and it cracked it in 2 seconds with the default settings of aircrack-ng 1.0 rc1... ??? lol

Anyways, mixed success... I'll let you guys know if I get injection working and can figure out what I was doing wrong, otherwise let me know if you're not yet to the point I'm at and need elaboration on something.

casper27 2009-06-02 19:11

Re: rt73 + aireplay-ng = packet injection
 
So does anyone know if a patch for the tablets internal NIC driver is possible or is it still wishfull thinking.

luddek 2009-08-10 16:19

Re: rt73 + aireplay-ng = packet injection
 
Has anyone got the rt73.ko and rt73.bin for 2.6.21?

Edit: found them here http://wiki.maemo.org/USB_to_ethernet_networking

cerealpirate 2009-08-20 19:57

Re: rt73 + aireplay-ng = packet injection
 
mrgreaper while your at it you need to "Report" Rapidshare.com for hosting millions of illegal files !!!!

Also you cant stop information ....Freedom of speech also means written words..... if not what about all the def people out there ???


All times are GMT. The time now is 13:16.

vBulletin® Version 3.8.8