Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 65 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow Finding hidden SSID
EH-Net
May 26, 2012, 02:48:45 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Finding hidden SSID  (Read 10345 times)
0 Members and 1 Guest are viewing this topic.
Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« on: March 16, 2011, 11:46:24 AM »

Hi all,

How do you find a hidden ssid with the aircrack suit ?

Thanks
Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #1 on: March 16, 2011, 11:49:52 AM »

I personally just fire up and use Kismet, first, and leave it running in the background, to watch things, while using aircrack suite for hacking wireless.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« Reply #2 on: March 16, 2011, 12:11:05 PM »

is there anyway to do it with aircrack suit ?
Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #3 on: March 16, 2011, 01:55:52 PM »

Exerpt from:  http://www.aircrack-ng.org/doku.php?id=aireplay-ng

Hidden SSIDs "<length: ?>"

Many aireplay-ng commands require knowing the SSID. You will sometimes see ”<length: ?>” as the SSID on the airodump-ng display. This means the SSID is hidden. The ”?” is normally the length of the SSID. For example, if the SSID was “test123” then it would show up as ”<length: 7>” where 7 is the number of characters. When the length is 0 or 1, it means the AP does not reveal the actual length and the real length could be any value.

To obtain the hidden SSID there are a few options:

    *
      Wait for a wireless client to associate with the AP. When this happens, airodump-ng will capture and display the SSID.
    *
      Deauthenticate an existing wireless client to force it to associate again. The point above will apply.
    *
      Use a tool like mdk3 to bruteforce the SSID.

Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
chrisj
Hero Member
*****
Offline Offline

Posts: 997


View Profile
« Reply #4 on: March 16, 2011, 07:48:17 PM »

Like Hayabusa said, aircrack an do it if you wait long enough, or make your attack known. Kismet isn't that hard to use. It's also useful for doing better wireless audits of the area around you.
Logged

OSWP, Sec+
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #5 on: March 16, 2011, 08:37:46 PM »

 Wink <nods head in agreement>  Really, if you have tools available, why not use them.  If you're to be a good pentester, you can count on building a large tool library (or at least, knowledge thereof.)  No sense in re-inventing the wheel, sometimes, if a tool exists that will work, quickly.  

(That said, Kismet is doing the same thing that 'waiting' with airodump, etc, would do, in that ANY tool is only going to show you a non-broadcasting SSID when a client connects to it.  So, regardless, it's a matter of patience...)  But Kismet displays it all, nicely, once it sees it.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
WCNA
Full Member
***
Offline Offline

Posts: 182



View Profile
« Reply #6 on: March 16, 2011, 09:47:54 PM »

Speaking of good tools, Colasoft's CAPSA wireless tool just came out. It's a nice alternative to AirPcap (monitor mode), lots of cool features.
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
TheXero
Full Member
***
Offline Offline

Posts: 112


Try Harder!


View Profile WWW
« Reply #7 on: March 17, 2011, 06:04:38 AM »

Dude you're in luck Smiley

Check out this video on my website http://www.thexero.co.uk/?p=48

In that video I find a hidden network and use the aireplay module to discover the SSId for the network by de-authenticating a client.

~TheXero
Logged

albatr0ss
Newbie
*
Offline Offline

Posts: 12


View Profile WWW
« Reply #8 on: November 17, 2011, 06:16:17 AM »

I wrote a script to try to bruteforce hidden ssids even when no clients are connected.

http://www.albatr0ss.it/2011/10/28/identifying-hidden-ssids/

In the post you'll find a video demoing the usage of the script.
Logged

OSWP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.132 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.