reinj attack

"slugbait" <[email protected]> Mon, 02 Jun 2003 11:37:56 -0400
Newsgroups gmane.network.wireless.bsd.airtools
Message-ID <[email protected]>
I've had some success with this tool after monkeying with the code a
bit.  I'm using OpenBSD-3.2 with h1kari's kernel patches and the 200mW
Senao card.  

I ran the code as-is while sniffing from a second box and saw the "test
injections" of an arp packet and the responses.  reinj apparently did
not see the responses, because it stopped injecting and continued to
look for another packet.  To get it to work, I commented out the
"response checking" sections of the code and just started blasting away.  

This worked, but is obviously not a good solution.  Have any unpublished
improvements to the code been made?  I'm currently developing my own
tool based on this technique, but I'd like to avoid wheel reinvention  ;)

I have lots of hardware in my lab, so I've been testing different
configs with varying degrees of success.  Linksys WAPs tend to choke
when the rate is set below 5 in the command line, but my Cisco 350
handled it just fine.  Has anyone else had success with this?

slugbait