Results 1 to 5 of 5

Thread: Packet Relay Problem

  1. #1
    Just burned his ISO Blind-Summit's Avatar
    Join Date
    Jan 2010
    Location
    Norwich, England
    Posts
    5

    Question Packet Relay Problem

    Hi,

    Been having trouble trying to find out why I am not getting the response I expect from aireplay with the -2 option. For example, this is what I expect:

    Code:
     Read 4 packets...
          Size: 68, FromDS: 0, ToDS: 1 (WEP)
     
               BSSID  =  ##:##:##:##:##:##
           Dest. MAC  =  FF:FF:FF:FF:FF:FF
          Source MAC  =  ##:##:##:##:##:##
     
          0x0000:  0841 de00 0014 6c7e 4080 000f b534 3030  .A....l~@....400
          0x0010:  ffff ffff ffff 4045 d16a c800 6f4f ddef  ......@E.j..oO..
          0x0020:  b488 ad7c 9f2a 64f6 ab04 d363 0efe 4162  ...|.*d....c..Ab
          0x0030:  8ad9 2f74 16bb abcf 232e 97ee 5e45 754d  ../t....#...^EuM
          0x0040:  23e0 883e                                #..>
    The destination mac is FF:FF:FF:FF:FF:FF (a broadcast) and the packet also contains the correct ffffff data.

    When I run this on another AP, I seem to get a different Dest. Mac -> 01:00:5E:00:00:01 which seems to have something to do with a multicast if I have understood this correctly. It doesn't broadcast to FF:FF:FF:FF:FF:FF and I don't see the correct data in the packet (as per the example)

    The first AP only takes ~ 20k IVs to bypass the WEP - but this one I can collect 200k IVs and it still won't budge.

    I'm interested to know how they can both relay packets but aircrack only breaks one key. I have done a bit of research but can't seem to get anywhere with this. I have tried changing the fudge factor in aircrack, but I am thinking it's more to do with invalid IVs being captured - or maybe the relay isn't actually working.

    These are both my routers before anyone asks - One of which is actually in use, and the other is from a box of random hardware that I can't find a home for!

    Any help would be most appreciated,

    Thanks.

  2. #2
    Super Moderator Archangel-Amael's Avatar
    Join Date
    Jan 2010
    Location
    Somewhere
    Posts
    8,012

    Default

    BackTrack Linux


    Aircrack-ng


    Take the link out of your signature it is against the rules.


    EDIT: Never mind I did it for you.
    I would suggest a re read of the rules you agreed to uphold.
    To be successful here you should read all of the following.
    ForumRules
    ForumFAQ
    If you are new to Back|Track
    Back|Track Wiki
    Failure to do so will probably get your threads deleted or worse.

  3. #3
    Just burned his ISO Blind-Summit's Avatar
    Join Date
    Jan 2010
    Location
    Norwich, England
    Posts
    5

    Default

    Sorry about the signature. It was just a link to the Linux counter site (I had hoped to have the little image badge but the BB code didn't work). Thought it was harmless enough, but yes, I missed the signature rules - sorry.

    I have searched, but can't seem to find any related topics. I am not a complete beginner, and have searched here and on google for aireplay/aircrack. I have read through the aireplay wiki and have tried several different options for the command but to no avail.

    I know you get a lot of timewasters and impatient folk here, but I honestly feel like I could use a little help. I have done enough homework to fake-auth, replay and then crack one of my routers, but not the other.

    I'll keep on reading, but surely this is a genuine help request and not just a "can't be bothered to learn" post?

  4. #4
    Super Moderator Archangel-Amael's Avatar
    Join Date
    Jan 2010
    Location
    Somewhere
    Posts
    8,012

    Default

    No one is questioning your willingness to learn.
    I gave you the link to our new forum, if you expect help with BT4 then go there.
    You will need to have the latest version of BT.
    Help for aircrack is also available on their site.
    To be successful here you should read all of the following.
    ForumRules
    ForumFAQ
    If you are new to Back|Track
    Back|Track Wiki
    Failure to do so will probably get your threads deleted or worse.

  5. #5
    Just burned his ISO Blind-Summit's Avatar
    Join Date
    Jan 2010
    Location
    Norwich, England
    Posts
    5

    Default

    Thanks - I'm already registered on the new forum - hopefully it will pick up soon.

    I'll ask around on the aircrack site and see what people suggest.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •