Many thanks for your reply muts.
please be a bit more descriptive about your specific hardware.
Apologies; MacBookAir 3,2
Code:
root@bt:~# lspci -vnn | grep 14e4
01:00.0 Network controller [0280]: Broadcom Corporation Device [14e4:4353] (rev 01)
__________________________________________________ ________________________________________
please take time to check things thoroughly.
???
__________________________________________________ ________________________________________
it isn't much use for anything else
While it's true that it passes the injection test (as it did in BT5);
Code:
root@bt:~# aireplay-ng -9 mon0
10:26:27 Trying broadcast probe requests...
10:26:27 Injection is working!
10:26:29 Found 2 APs
10:26:29 Trying directed probe requests...
10:26:29 00:25: etc
10:26:34 Ping (min/avg/max): 3.737ms/136.610ms/181.139ms Power: -89.56
10:26:34 18/30: 60%
10:26:34 00:13: etc
10:26:39 Ping (min/avg/max): 4.356ms/158.922ms/191.733ms Power: -57.16
10:26:39 25/30: 83%
I still have the old problem of not collecting data or handshakes in airodump-ng
Code:
BSSID PWR Beacons #Data, #/s CH MB ENC CIPHER AUTH ESSID
00:25:etc -47 928 0 0 11 54e. WPA2 CCMP PSK
00:13:etc -65 883 0 0 1 54 WPA2 CCMP PSK
00:60:etc -77 374 0 0 6 54e WPA2 CCMP PSK
74:91:etc -91 129 0 0 6 54e. OPN
I have confirmed there is no data by wireshark inspection, and also by comparing to a simultaneous capture from another card. Also the same result when capturing directly from wireshark, so it isn't a problem specific to airodump-ng.
Deauth attacks are successful (but no handshakes captured).
It will not associate with my AP after macchanging.
So, for me, brcmsmac is not (yet) useful in a real world setting, when compared to USB cards or to the excellent iwlagn in my other laptop.