Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 23 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Wirelessarrow Finding hidden SSID
EH-Net
May 26, 2013, 03:56:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Finding hidden SSID  (Read 30918 times)
0 Members and 1 Guest are viewing this topic.
millwalll
Guest
« on: March 16, 2011, 11:46:24 AM »

Hi all,

How do you find a hidden ssid with the aircrack suit ?

Thanks
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #1 on: March 16, 2011, 11:49:52 AM »

I personally just fire up and use Kismet, first, and leave it running in the background, to watch things, while using aircrack suite for hacking wireless.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
millwalll
Guest
« Reply #2 on: March 16, 2011, 12:11:05 PM »

is there anyway to do it with aircrack suit ?
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #3 on: March 16, 2011, 01:55:52 PM »

Exerpt from:  http://www.aircrack-ng.org/doku.php?id=aireplay-ng

Hidden SSIDs "<length: ?>"

Many aireplay-ng commands require knowing the SSID. You will sometimes see ”<length: ?>” as the SSID on the airodump-ng display. This means the SSID is hidden. The ”?” is normally the length of the SSID. For example, if the SSID was “test123” then it would show up as ”<length: 7>” where 7 is the number of characters. When the length is 0 or 1, it means the AP does not reveal the actual length and the real length could be any value.

To obtain the hidden SSID there are a few options:

    *
      Wait for a wireless client to associate with the AP. When this happens, airodump-ng will capture and display the SSID.
    *
      Deauthenticate an existing wireless client to force it to associate again. The point above will apply.
    *
      Use a tool like mdk3 to bruteforce the SSID.

Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #4 on: March 16, 2011, 07:48:17 PM »

Like Hayabusa said, aircrack an do it if you wait long enough, or make your attack known. Kismet isn't that hard to use. It's also useful for doing better wireless audits of the area around you.
Logged

OSWP, Sec+
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #5 on: March 16, 2011, 08:37:46 PM »

 Wink <nods head in agreement>  Really, if you have tools available, why not use them.  If you're to be a good pentester, you can count on building a large tool library (or at least, knowledge thereof.)  No sense in re-inventing the wheel, sometimes, if a tool exists that will work, quickly.  

(That said, Kismet is doing the same thing that 'waiting' with airodump, etc, would do, in that ANY tool is only going to show you a non-broadcasting SSID when a client connects to it.  So, regardless, it's a matter of patience...)  But Kismet displays it all, nicely, once it sees it.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
WCNA
Full Member
***
Offline Offline

Posts: 187



View Profile
« Reply #6 on: March 16, 2011, 09:47:54 PM »

Speaking of good tools, Colasoft's CAPSA wireless tool just came out. It's a nice alternative to AirPcap (monitor mode), lots of cool features.
Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
TheXero
Full Member
***
Offline Offline

Posts: 112


Try Harder!


View Profile WWW
« Reply #7 on: March 17, 2011, 06:04:38 AM »

Dude you're in luck Smiley

Check out this video on my website http://www.thexero.co.uk/?p=48

In that video I find a hidden network and use the aireplay module to discover the SSId for the network by de-authenticating a client.

~TheXero
Logged

albatr0ss
Newbie
*
Offline Offline

Posts: 12


View Profile WWW
« Reply #8 on: November 17, 2011, 06:16:17 AM »

I wrote a script to try to bruteforce hidden ssids even when no clients are connected.

http://www.albatr0ss.it/2011/10/28/identifying-hidden-ssids/

In the post you'll find a video demoing the usage of the script.
Logged

OSWP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.07 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.