Re: reinj attack
h1kari <[email protected]> Mon, 02 Jun 2003 11:53:00 -0700
| Newsgroups | gmane.network.wireless.bsd.airtools |
|---|---|
| Message-ID | <BB00EB1C.C872%[email protected]> |
slugbait, I haven't done any more recent work on this so you're more than welcome to work on any improvements or any new tools if you want. As for the netbsd patches it looks like the guy that was working on it isn't going to be able to do it in a timely fashion, so I'm going to try and hack it together later this week. Another thing.. Michael Rossberg (kismac) has been developing the reinjection stuff into kismac and might have found out some more specifics with injection and stuff, so it might be worth while talking to him. Either way, let me know how things develop with your research in case there's any way I can help. Cheers, -h1kari On 6/2/03 8:37, "slugbait" <[email protected]> wrote: > I've had some success with this tool after monkeying with the code a > bit. I'm using OpenBSD-3.2 with h1kari's kernel patches and the 200mW > Senao card. > > I ran the code as-is while sniffing from a second box and saw the "test > injections" of an arp packet and the responses. reinj apparently did > not see the responses, because it stopped injecting and continued to > look for another packet. To get it to work, I commented out the > "response checking" sections of the code and just started blasting away. > > This worked, but is obviously not a good solution. Have any unpublished > improvements to the code been made? I'm currently developing my own > tool based on this technique, but I'd like to avoid wheel reinvention ;) > > I have lots of hardware in my lab, so I've been testing different > configs with varying degrees of success. Linksys WAPs tend to choke > when the rate is set below 5 in the command line, but my Cisco 350 > handled it just fine. Has anyone else had success with this? > > slugbait > _______________________________________________ > Bat mailing list > [email protected] > http://lists.dachb0den.com/mailman/listinfo/bat > >