Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 51 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Wireless
Capture WEP and WPA association / authentication traffic
EH-Net
May 21, 2013, 09:53:12 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Wireless
(Moderator:
don
) >
Capture WEP and WPA association / authentication traffic
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Capture WEP and WPA association / authentication traffic (Read 12153 times)
0 Members and 1 Guest are viewing this topic.
Ignatius
Jr. Member
Offline
Posts: 91
Capture WEP and WPA association / authentication traffic
«
on:
September 27, 2009, 01:25:27 PM »
I'm interested in capturing my own WEP and WPA association and authentication traffic so I can study and then understand it. I set up two laptops, one running BT3 live CD and the other Windows XP with a Netgear WG511T PCMCIA wireless card.
I managed to get the capturing laptop configured and authenticated to my wireless router (WPA). I also got my second laptop authenticated but didn't see any of the association/authentication packets when I ran Wireshark in BT3. I set the capturing laptop wireless in promiscuous mode. This is Intel PRO/Wireless 2200BG.
I ran the test again but didn't authenticate my capturing laptop first. It didn't make any difference as I didn't see any traffic when the second laptop authenticated.
Finally, I captured traffic when the capturing laptop authenticated. All I saw were a series of EAPOL frames. There were no beacons, probes or frames containing the SSID. I have seen a pcap file of the authentication process so I know that these additional frames should be present.
I just wonder if my Intel Wireless card isn't playing nicely with Wireshark. Any tips? I hasten to add that this is for my own education, rather than illicit activity in a coffee shop (etc.)!
«
Last Edit: September 27, 2009, 01:30:03 PM by don
»
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Capture WEP and WPA association / authentication traffic
«
Reply #1 on:
September 27, 2009, 09:31:47 PM »
I am making some assumptions because I am not quite clear as to what is connected to what in your configuration. I am assuming that the Intel 2200 BG is card is in the laptop that is running BT3. You are trying to capture authentication traffic from the Windows box to the AP from the BT3 box. If this is incorrect, please let us know.
It could be a driver issue with the Intel cards related to promiscuous mode. I have had nothing but trouble with them. I would try using BT4 Pre Release. I have much better results with wireless in BT4 than BT3. Which driver is the card using? (lspci -k and look for the kernel module).
Logged
~~~~~~~~~~~~~~
Ketchup
Ignatius
Jr. Member
Offline
Posts: 91
Re: Capture WEP and WPA association / authentication traffic
«
Reply #2 on:
September 28, 2009, 05:02:24 AM »
Thank you for the guidance. Your interpretation of the configuration is correct.
I ran lspci -k in BT3 and got the following:
Code:
bt ~ # lspci -k
lspci: invalid option -- k
Usage: lspci [<switches>]
so I tried lspci -v and got the following related to the ethernet and wireless:
Code:
02:08.0 Ethernet controller: Intel Corporation 82801DB PRO/100 VE (MOB) Ethernet Controller (rev 83)
Subsystem: Sony Corporation Unknown device 8140
Flags: bus master, medium devsel, latency 66, IRQ 9
Memory at d0200000 (32-bit, non-prefetchable) [size=4K]
I/O ports at 4000 [size=64]
Capabilities: [dc] Power Management version 2
02:0b.0 Network controller: Intel Corporation PRO/Wireless 2200BG Network Connection (rev 05)
Subsystem: Intel Corporation Unknown device 2753
Flags: bus master, medium devsel, latency 64, IRQ 9
Memory at d0201000 (32-bit, non-prefetchable) [size=4K]
Capabilities: [dc] Power Management version 2
I couldn't see anything relating to kernel module or drivers though.
I'll see if I can get BT4 to work. I suppose my alternative is to get a USB or PCMCIA wireless card which will work. I'm based in the UK so would prefer to get something here, rather than have to order from the US (with additional shipping charges).
«
Last Edit: September 28, 2009, 05:03:58 AM by Ignatius
»
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Capture WEP and WPA association / authentication traffic
«
Reply #3 on:
September 28, 2009, 07:31:25 AM »
Try lspci -vv. I don't remember what the correct switch is in BT3 version Linux. You can also run lscpi --help | grep -i kernel to see if anything comes up on the appropriate switch.
Can you switch it up and boot the laptop with the PCMCIA wireless card from the BT3 disc? If you can capture traffic there, you know it has something to do with the driver or the card.
Logged
~~~~~~~~~~~~~~
Ketchup
Ignatius
Jr. Member
Offline
Posts: 91
Re: Capture WEP and WPA association / authentication traffic
«
Reply #4 on:
September 28, 2009, 08:51:18 AM »
I wondered if the -k switch was used in other versions ... I've managed to get BT4 working and the lspci -k output is:
Code:
02:08.0 Ethernet controller: Intel Corporation 82801DB PRO/100 VE (MOB) Ethernet Controller (rev 83)
Kernel driver in use: e100
02:0b.0 Network controller: Intel Corporation PRO/Wireless 2200BG [Calexico2] Network Connection (rev 05)
Kernel driver in use: ipw2200
Kernel modules: ipw2200
I'm not even able to get connected to my wireless (WPA) card connected now though! I'll get back into BT3, copy the entire wpa_supplicant.conf file and try that in BT4.
Unfortunately, the older laptop (the one with the PCMCIA card) won't run BT. It was designed for W98 (yes, that old) and has 128MB RAM. I'll try the PCMCIA card in the newer laptop though to see if it will pick up traffic from my wireless router.
BTW, do you have any recommendations for wireless cards (USB or PCMCIA) which will "play" with BT without any hassle? I'm keen to capture the traffic so I can understand the authentication process.
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Capture WEP and WPA association / authentication traffic
«
Reply #5 on:
September 28, 2009, 10:24:19 AM »
Here is a list of wireless cards that are supported by BT and any associated issues. I use a Belkin USB stick that supports injection. Like just about anything there are only a few supported versions, and some work better than others. I bought mine because it cost me $25 US.
http://backtrack.offensive-security.com/index.php/HCL:Wireless
The card appears to be using the correct driver, ipw2200. I think that the wpa supplicant file should help with the association issue. However, you don't have to associate to capture wireless traffic. Have you tried running Wireshark yet on BT4? Do you get anything?
Logged
~~~~~~~~~~~~~~
Ketchup
Ignatius
Jr. Member
Offline
Posts: 91
Re: Capture WEP and WPA association / authentication traffic
«
Reply #6 on:
September 28, 2009, 04:07:37 PM »
Having got BT4 working, I tried connecting to my wireless router and could when I used the connection manager so it appears that the driver is correct but I still need to get the wpa_supplicant.conf file sorted. I set up the second laptop and got it to associate too but nothing was picked up by Wireshark. This is despite whether it was associated or not and whether it was in promiscuous mode or not.
I'll look into getting a second card from the list that you linked. I just wonder if it's a problem of my configuration of Wireshark so I might ask on their forum. I ran Kismet in BT3 (whilst not associated) and it picked up my home network, as expected, without any problems.
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Capture WEP and WPA association / authentication traffic
«
Reply #7 on:
September 28, 2009, 04:48:40 PM »
Hmm, this is a strange one. Try tcpdump instead of wireshark to see if there are any issues with the software config. You can also run airmon-ng to start the wifi card in promiscuous mode to make sure it is actually going into the mode.
Logged
~~~~~~~~~~~~~~
Ketchup
Ignatius
Jr. Member
Offline
Posts: 91
Re: Capture WEP and WPA association / authentication traffic
«
Reply #8 on:
October 11, 2009, 01:18:51 PM »
UPDATE (and sorry for not feeding back earlier!):
I've been pulling my hair out. I managed to get a second Netgear WG511T PCMCIA card and all the research that I did led me to believe that it *should* work to collect management frames. I looked into airmon-ng and issued:
ifconfig wlan0 down
airmon-ng start wlan0
which created a new entry in ifconfig -a (mon0)
I started Wireshark and collected using mon0. Lo and behold, there were beacons and probes! I switched back to my original WG511T card and it didn't work so I guess it's been a combination of a faulty card and the lack of my using airmon-ng. Before you (Ketchup) mentioned this, I assumed that I could change the mode of the card from within Wireshark.
As a non-Linux user, it's been a steep learning curve ... but one which has made me more determined to learn more!
Logged
alucian
Full Member
Offline
Posts: 225
Re: Capture WEP and WPA association / authentication traffic
«
Reply #9 on:
October 11, 2009, 01:51:28 PM »
WG511t works fine in backtrack. You can inject packets with it, I am using it and it is very good.
The better way to do it is to start airmon on the specific channel of your net
airmon-ng start wlan0 x (x is the channel)
In order to collect packets you should type:
airodump-ng -c x (x is the channel) --bssid AP_MAC -w name_capture_file mon0
-c and --bssid are optional, but like this you'll only capture the traffic for your ip.
This command will generate a file with the extension cap, wich you can open with wireshark. For more if type airodump-ng --help
About your old laptop, here is a list with the compatible laptops for backtrack 3:
http://backtrack.offensive-security.com/index.php/HCL:Laptops
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Ignatius
Jr. Member
Offline
Posts: 91
Re: Capture WEP and WPA association / authentication traffic
«
Reply #10 on:
October 12, 2009, 09:06:25 AM »
Thanks alucian. I'm using a live BT4 CD and I'm considering using an old laptop (within the HCL) to load BT4. I know that I can take an image to restore the laptop should I make any major configuration errors. I'm pleased that I have a card and appropriate commands which will allow me to collect the traffic that I'll need to learn about the association and authentication process.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(12) by
3xban
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.