Re: reinj attack

h1kari <[email protected]> Mon, 02 Jun 2003 11:53:00 -0700
Newsgroups gmane.network.wireless.bsd.airtools
Message-ID <BB00EB1C.C872%[email protected]>
slugbait,

I haven't done any more recent work on this so you're more than welcome to
work on any improvements or any new tools if you want. As for the netbsd
patches it looks like the guy that was working on it isn't going to be able
to do it in a timely fashion, so I'm going to try and hack it together later
this week.

Another thing.. Michael Rossberg (kismac) has been developing the
reinjection stuff into kismac and might have found out some more specifics
with injection and stuff, so it might be worth while talking to him. Either
way, let me know how things develop with your research in case there's any
way I can help.

Cheers,
-h1kari


On 6/2/03 8:37, "slugbait" <[email protected]> wrote:

> I've had some success with this tool after monkeying with the code a
> bit.  I'm using OpenBSD-3.2 with h1kari's kernel patches and the 200mW
> Senao card.  
> 
> I ran the code as-is while sniffing from a second box and saw the "test
> injections" of an arp packet and the responses.  reinj apparently did
> not see the responses, because it stopped injecting and continued to
> look for another packet.  To get it to work, I commented out the
> "response checking" sections of the code and just started blasting away.
> 
> This worked, but is obviously not a good solution.  Have any unpublished
> improvements to the code been made?  I'm currently developing my own
> tool based on this technique, but I'd like to avoid wheel reinvention  ;)
> 
> I have lots of hardware in my lab, so I've been testing different
> configs with varying degrees of success.  Linksys WAPs tend to choke
> when the rate is set below 5 in the command line, but my Cisco 350
> handled it just fine.  Has anyone else had success with this?
> 
> slugbait
> _______________________________________________
> Bat mailing list
> [email protected]
> http://lists.dachb0den.com/mailman/listinfo/bat
> 
>