Page 1 of 2 12 LastLast
Results 1 to 10 of 32

Thread: ALFA WIFI USB ISSUES IN VMWARE & Solution

Hybrid View

  1. #1
    Junior Member Headshot's Avatar
    Join Date
    Dec 2007
    Posts
    61

    Default ALFA WIFI USB ISSUES IN VMWARE & Solution

    Hi

    I got my ALFA Wireless USB stick today!! + a 2dBi antenna
    But none of the attacks are working properly.

    I'm running BT3 on VMware, i also tried live CD BT2 and BT3 but gave same results.

    Seems to be recognized by BT3 on insert / boot:

    Code:
    usb 1-1: new high speed USB device using ehci_hcd and address 3
    usb 1-1: configuration #1 chosen from 1 choice
    rtl8187: Enabling 14 channels.
    rtl8187: MAC chip version: 04
    rtl8187: Card type: AD
    rtl8187: Reported EEPROM chip is a 93c46 (1Kbit) 
    rtl8187: Card MAC address is 00:c0:ca:19:e1:11
    rtl8187: RF Chip ID: 05
    rtl8187: Card reports RF frontend Realtek 8225
    rtl8187: WW:This driver has EXPERIMENTAL support for this chipset.
    rtl8187: WW:use it with care and at your own risk and 
    rtl8187: WW:**PLEASE** REPORT SUCCESS/INSUCCESS TO andreamrl@tiscali.it
    rtl8187: This seems a new V2 radio
    rtl8187: PAPE from CONFIG2: 0
    rtl8187: Driver probe completed
    Seems good, ok lets run some tests.

    Code:
    iwlist wlan0 bitrate
    Current Bit Rate=11 Mb/s
    So that's good, nextup iwconfig:

    Code:
    wlan0     Link encap:Ethernet  HWaddr 00:**:**:**:**:11 (you get the idea)
              inet addr:192.168.1.108  Bcast:192.168.1.255  Mask:255.255.255.0 
              UP BROADCAST NOTRAILERS RUNNING MULTICAST  MTU:1500  Metric:1
              RX packets:690 errors:0 dropped:7220 overruns:0 frame:0
              TX packets:645 errors:0 dropped:0 overruns:0 carrier:0
              collisions:0 txqueuelen:1000 
              RX bytes:460993 (450.1 KiB)  TX bytes:235129 (229.6 KiB)
    So i am able to connect to a secure WEP router.
    So lets disconnect from that router and try to hack it.

    So lets bring everything down:
    Code:
    ifconfig wlan0 down
    airmon-ng stop wlan0 down
    
    Interface          Chipset          Driver
    wlan0              RTL8187         r8187 (monitor mode disabled)
    Ok, next i'm booting everything up.

    Code:
    airmon-ng start wlan0 4 (my router channel)
    //Outputs same as above only (monitor mode enabled)
    
    ifconfig wlan0 up
    Now everythings seems to work.
    I use airodump-ng on channel 4, and the bssid from my router, and it shows up perfectly and all connected stations.

    Now with all attacks most attacks start, and displaying normal.
    But when its start sending packets, the data wont go up...

    I tryed command, if you would like to view the outcome of a command please post wich attack Because the topic has text limit.

    If somebody could help me, i would really appreciate it.
    I thought buying this card would solve the problems i had with ipw3945.
    But it looks almost the same

    Thanks again for anyone who can help me out!
    01010111101001011101010101000010101010101
    10010100011010010010101010111010010111100
    ----------------
    Back|Track * Beginner :o

  2. #2
    Senior Member imported_spankdidly's Avatar
    Join Date
    Feb 2006
    Posts
    1,031

    Default

    Any clients connected? Try the fragmentation attack. Good article over at aircrack-ng.org (I think that's where it's at).
    I felt like bending the bars back, and ripping out the window frames and eating them. yes, eating them! Leaping, leaping, leaping! Colonics for everyone! All right! You dumb*sses. I'm a mental patient. I'm *supposed* to act out!

  3. #3
    Junior Member bwise's Avatar
    Join Date
    Nov 2007
    Posts
    69

    Default

    didn't quite get what your problem is , can you give us more details please ?
    i own an alfa usb dongle also and every attack i've tried seems to work perfectly fine on vmware 6 with bt3

    edit: and the injection rate is good also

  4. #4
    Member
    Join Date
    Mar 2007
    Posts
    204

    Default

    Please post EXACTLY what commands you are trying to perform.

    Your using the USB stick one right? not the Ciggarett packet sized 500mw version?

  5. #5
    Junior Member Headshot's Avatar
    Join Date
    Dec 2007
    Posts
    61

    Default

    Quote Originally Posted by spankdidly View Post
    Any clients connected? Try the fragmentation attack. Good article over at aircrack-ng.org (I think that's where it's at).
    Followed:
    http://www.aircrack-ng.org/doku.php?id=fragmentation

    Result:
    Ok, a other computer of mine is connected, and refreshing the page google about every 10 sec.

    First i run:
    Code:
    aireplay-ng -0 1 -a 00:11:22:33:44:55 (target example) wlan0
    
    right away it outputs:
    
    (i know there's more stuff here ;), just keeping it short)
    Assocation succesful :-)
    Now after that i'm running :
    Code:
    aireplay-ng -5 -b 00:11:22:33:44:55 (target example) -h 00:33:44:55:66:77 (My MAC example) wlan0
    Reading packets, pressing Y to accept:

    Code:
    Data packet found!
    Sending fragment packet
    No answer, repeating...
    Trying a LLC NULL packet
    And that keeps repeating itself

    ---------USB INFO-----------
    Alfa Network
    Model: UWUS036E
    01010111101001011101010101000010101010101
    10010100011010010010101010111010010111100
    ----------------
    Back|Track * Beginner :o

  6. #6
    Member
    Join Date
    Mar 2007
    Posts
    204

    Default

    I think its probably a typo but thats the de-auth command not the fakeauth.

    And your not using the Alfa 500mw adapter but its little brother, i didnt even realise that was the same chipset.

    Quote Originally Posted by Headshot View Post
    Followed:
    http://www.aircrack-ng.org/doku.php?id=fragmentation

    Result:
    Ok, a other computer of mine is connected, and refreshing the page google about every 10 sec.

    First i run:
    Code:
    aireplay-ng -0 1 -a 00:11:22:33:44:55 (target example) wlan0
    
    right away it outputs:
    
    (i know there's more stuff here ;), just keeping it short)
    Assocation succesful :-)
    Now after that i'm running :
    Code:
    aireplay-ng -5 -b 00:11:22:33:44:55 (target example) -h 00:33:44:55:66:77 (My MAC example) wlan0
    Reading packets, pressing Y to accept:

    Code:
    Data packet found!
    Sending fragment packet
    No answer, repeating...
    Trying a LLC NULL packet
    And that keeps repeating itself

    ---------USB INFO-----------
    Alfa Network
    Model: UWUS036E

  7. #7
    Developer balding_parrot's Avatar
    Join Date
    May 2007
    Posts
    3,399

    Default

    Quote Originally Posted by Headshot View Post
    Hi

    I got my ALFA Wireless USB stick today!! + a 2dBi antenna
    But none of the attacks are working properly.

    I'm running BT3 on VMware, i also tried live CD BT2 and BT3 but gave same results.

    Seems to be recognized by BT3 on insert / boot:

    Code:
    usb 1-1: new high speed USB device using ehci_hcd and address 3
    usb 1-1: configuration #1 chosen from 1 choice
    rtl8187: Enabling 14 channels.
    rtl8187: MAC chip version: 04
    rtl8187: Card type: AD
    rtl8187: Reported EEPROM chip is a 93c46 (1Kbit) 
    rtl8187: Card MAC address is 00:c0:ca:19:e1:11
    rtl8187: RF Chip ID: 05
    rtl8187: Card reports RF frontend Realtek 8225
    rtl8187: WW:This driver has EXPERIMENTAL support for this chipset.
    rtl8187: WW:use it with care and at your own risk and 
    rtl8187: WW:**PLEASE** REPORT SUCCESS/INSUCCESS TO andreamrl@tiscali.it
    rtl8187: This seems a new V2 radio
    rtl8187: PAPE from CONFIG2: 0
    rtl8187: Driver probe completed
    Sounds like this may be one of those cards that Xploitz was talking about a week or two ago with the different chipset.

    Open it up and check the chipset, they open very easily without any damage.

  8. #8
    Senior Member imported_spankdidly's Avatar
    Join Date
    Feb 2006
    Posts
    1,031

    Default

    Quote Originally Posted by balding_parrot View Post
    Sounds like this may be one of those cards that Xploitz was talking about a week or two ago with the different chipset.

    Open it up and check the chipset, they open very easily without any damage.
    Boom Headshot!
    I felt like bending the bars back, and ripping out the window frames and eating them. yes, eating them! Leaping, leaping, leaping! Colonics for everyone! All right! You dumb*sses. I'm a mental patient. I'm *supposed* to act out!

  9. #9
    Junior Member Headshot's Avatar
    Join Date
    Dec 2007
    Posts
    61

    Default

    @merlin051
    Sorry Typo mistake
    I did enter -1 but i'm typing this over from my other screen thats running backtrack

    Specifications from the website i bought it:
    Standards IEEE 802.11g/b
    Bus Type USB 2.0 Type A
    Frequency Band 2.4000~2.4835GHz (Industrial Scientific Medical Band)
    Modulation OFDM with BPSK, QPSK, 16QAM, 64QAM (11g)
    BPSK, QPSK, CCK (11b)
    Data Rate 54/48/36/24/18/12/11/9/6/5.5/2/1Mbps auto fallback
    Securities 64/128-bit WEP Data Encryption, WPA (TKIP with IEEE 802.1x), AES
    Antenna External RPSMA Antenna
    Drivers Windows 98SE/Me/2000/XP/2003 Server/Vista/Win CE/
    MAC OS/Linux
    LEDs Link/Activity
    Transmit Power 19dBm
    Receive Sensitivity -89.5dBm@1Mbps
    Dimension 10(H) x 28(W) x 90(L) mm
    Temperature 32~122°F (0 ~50°C)
    Humidity 10-95% (NonCondensing)
    Certification FCC , CE
    01010111101001011101010101000010101010101
    10010100011010010010101010111010010111100
    ----------------
    Back|Track * Beginner :o

  10. #10
    Developer
    Join Date
    Mar 2007
    Posts
    6,124

    Default

    I didn't see you post the result of a -9 injection test. Headshot.

    Also try the -4 attack

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •