Results 1 to 5 of 5

Thread: Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

  1. #1
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    5

    Question Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

    Hi,

    I've been looking through numerous sources to try and track down what the problem could be but I'm stumped. Using Backtrack 4 final and tried this on both USB and VMWare versions (VMware on workstation and USB thumbdrive on HP laptop).

    I've tested ARP poisoning (MITM with Ettercap) with 4 wireless cards but can only get it to work on one.

    Cards:

    1) AWUS036H 500mW (tried both rtl8187 & r8187 modules) - No poisoning
    2) AWUS036H 1000mW (tried both rtl8187 & r8187 modules) - No posoning
    3) Internal HP laptop wifi (Intel 4965 according to airmon-ng) - No poisoning
    4) USB Air Live Turbo-G (Ralink 2573 USB rt73usb) - Poisoning process succesful!

    I've made the changes to ettercap.conf:

    a) ec_uid and ec_gid is set to root (0)
    b) Uncommented the two lines "redir_command_on = "iptables..." and "redir_command_off = "iptables..."

    Using Wireshark I can see that requests are coming through even if it says the "No ARP poisoning at all" in ettercap, but it significantly hinders the connection between Target 1 and Target 2. Websites fail to load up and slow to a crawl. With the Air Live USB card it works like a charm, no slow downs or timeouts and logging into sites like GMAIL, Facebook etc all comes up with the typical certificate warning where I don't have any of that luck with the other 3 cards.

    I've tested ARP injection with the AWUS036H cards and they both inject without any problems (aireplay-ng -9 <interface>). Quite easily cracked WEP and can use all 4 cards with WICD without any problems.

    Why would my "better" cards be struggling? Anyone with an Alfa poisoning ARP succesfully? Any other information I can provide to clarify my setup?

    Any help much appreciated!
    Last edited by mythan; 02-24-2010 at 11:31 PM.

  2. #2
    My life is this forum Snayler's Avatar
    Join Date
    Jan 2010
    Posts
    1,418

    Default Re: Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

    I tried this with a Alfa'36h 1000mw and the same happens to me. With my TP-Link WN422G everything works fine. I'll try to investigate further and I will post back once I get the results.
    Last edited by Snayler; 02-27-2010 at 01:38 PM. Reason: Correcting a mistake

  3. #3
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    5

    Default Re: Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

    Hi Snayler,

    Strange eh? If this is a wider issue I'm surprised it hasn't been mentioned earlier (unless somebody owns me with a link to a thread/URL where this has been discussed before).

    I'd be very keen to find out what the result of your investigation is. I thought at some point it may have been the access point (Linksys WAG54GP2) but I get the same result on a Netgear WGR614 with the same cards.

    Thanks for looking into this.

  4. #4
    Member
    Join Date
    Jan 2010
    Posts
    102

    Default Re: Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

    Works for me with AWUS036H =P

  5. #5
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    5

    Default Re: Ettercap ARP poison - Alfa AWUS036H fail but Air Live Turbo-G el cheapo works?

    Hi MassAppeal,

    1) Did you make any changes (driver module?), application updates etc to your Backtrack 4 USB/VMWare distro?
    2) What type of encryption does your AP use? I've tested it on WEP and WPA2.

    Following is basically what I'd do:

    a) ifconfig <int> down
    b) macchanger -r <int>
    c) wicd start
    d) wicd-client, connect it up to access point, verify it's ok by pinging gateway, test gateway by browsing to random website.
    e) startup ettercap GTK, unified sniffing, start sniffing, scan for hosts & set found gateway and client, activate ARP poisoning

    Works fine with AirLive Turbo, fails with Alfa

    It's like the Alfa has trouble forwarding the packets through causing timeouts between the two targets. As soon as I switch of ARP poisoning, *poof*, all back to normal between client and gateway.

    You do any other steps or in a different order?

    Thank you

Similar Threads

  1. ALFA Networks AWUS036H
    By MassAppeal in forum HardWare Compatibility List
    Replies: 26
    Last Post: 05-01-2010, 04:46 AM
  2. ALFA AWUS036H Support Power ?
    By KherKhere in forum Beginners Forum
    Replies: 2
    Last Post: 02-21-2010, 09:31 PM
  3. Alfa AWUS036H can't connect to internet
    By horama in forum Beginners Forum
    Replies: 2
    Last Post: 02-10-2010, 05:12 AM
  4. Issue: ALFA AWUS036H WPA Handshake!
    By MassAppeal in forum BackTrack Bugs
    Replies: 2
    Last Post: 01-19-2010, 08:08 AM
  5. ISO Image ALFA-AWUS036H
    By MassAppeal in forum BackTrack Bugs
    Replies: 2
    Last Post: 01-17-2010, 10:52 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •