Forgot to mention that I am using a ORiNOCO card (8470-FC) with updated madwifi drivers, updated kismet, and updated aircrack -- using the tut from TheGreatVirus: http://forums.remote-exploit.org/showthread.php?t=569.
Thanks!
One of my test routers (DLink DI-624, with no clients) has recently stopped showing up in airodump and kismet. Instead of the random ESSID that used to show, it only shows "<length: 12>." The strange thing is that I have run several WEP breaks on this particular device without any issues. Even with SSID Broadcast disabled, airodump & kismet were both usually able to discover (or decloak) in a matter of seconds. I have let airodump run for hours with no results. The PWR is well above 30-35 range.
I am curious how I can get around this, but even more importantly... I am wondering what setting in the router could really keep this device "invisible" from BT. Additionally, BT is the only one that seems to have any problems. I have an iPaq with WiFiFoFum plus all of my Windows machines see this device without any problem.
Any ideas?
Thanks!
Forgot to mention that I am using a ORiNOCO card (8470-FC) with updated madwifi drivers, updated kismet, and updated aircrack -- using the tut from TheGreatVirus: http://forums.remote-exploit.org/showthread.php?t=569.
Thanks!
I got a more up to date video for the -3 and a video on the -4 attack that may aide you. There is no setting in the router that I'm aware of that will "elude" airodump or Kismet from picking up the ESSID in question.
Try running
aireplay-ng -0 10 -a APMAC ath0
to reveal the ESSID.
Also in your routers settings depending on the name brand and model...the Broadcast ssid is the only "cloaking" feature I'm aware of.
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]
newest aircrack doesn't need the -e switch to associate, so you can forgot essid discovery, it's useless
Watch your back, your packetz will belong to me soon... xD
BackTrack : Giving Machine Guns to Monkeys since 2006
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]
Any idea as to why it is cloaked from BT2, but XP Zero Config and/or Windows Mobile can pick it up right away?
To be completely fair, the XP machine has connected to this AP in the past (as a legitimate client). So, I'm not sure if something is cached somewhere. But the Windows Mobile device was just hard reset and reloaded about a week ago.
Thanks!
Here is another wierd tidbit. Airodump has ben running for ~2 hours with no luck. I turned on the scan from the iPaq and immediately airodump picked up the ESSID. Apparently something in an exchange that the iPaq tried to make helped.
I'd expose the "idiot", but I figure if he wanted me to blab to the whole world who it was that gave me a HD for FREE..that person would have said its ok to... But this person didn't say if it was ok or not, and I'm no snitch...so, untill they say its ok, my lips are sealed. I respect people, and I figure if I did something like that for someone, I wouldn't want others to know that I did it because then other people might think I was rich..and I'd get flooded with "I'm so poor.....please buy me a new Hard Drive" PM's All the time..and I don't want that to happen to this person. So unless this person tells me its cool..its our little secrete.![]()
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]