Many thanks! I've just noticed a thing: shouldn't it be: aireplay-ng -1 0 -e [AP ESSID] -a [AP BSSID] -h [N900 MAC Address] wlan0 I mean, you must specify AP ESSID (name)? I wrote once in Aircrack forum (look at the bottom): http://forum.aircrack-ng.org/index.p...=3309.msg18601 asking why it was necessary specify network name, and they answered me it was part of the standards. In fact, if ESSID is hidden, you must find it, first.