Plugins 2500/2501 and 16800/16801 are deprecated
#71
Before you start hcxdumptool make sure that all services that take access to the device are stopped (as mentioned in --help).
Reply
#72
Thank you so much devs. I have run the commands needed and I noticed there is a line saying

BPF is unset! ...

How can I enable this? Thank you
Reply
#73
hcxdumptool use the Berkeley Packet Filter (BPF) to select a target or to protect own devices. Its entire attack behavior can be controlled via this BPF.

If the filter is not applied, hcxdumptool will attack everything in range merciless.
You'll see this warning:
Code:
BPF is unset! Make sure hcxdumptool is running in a 100% controlled environment!

A (very) simple BPF code is explained in -h):
Code:
--bpfc=<filter>: compile Berkeley Packet Filter (BPF) and exit $ hcxdumptool --bpfc="wlan addr3 112233445566" > filter.bpf see man pcap-filter --bpf=<file> : input Berkeley Packet Filter (BPF) code (maximum 4096 instructions) in tcpdump decimal numbers format see --help for more information
and --help
Code:
Berkeley Packet Filter: ----------------------- tcpdump decimal numper format: example: tcpdump high level compiler: $ tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -ddd > filter.bpf see man pcap-filter example: bpf_asm low level compiler $ bpf_asm filter.asm | tr ',' '\n' > filter.bpf see https://www.kernel.org/doc/html/latest/networking/filter.html example: bpfc low level compiler: $ bpfc -f tcpdump -i filter.asm > filter.bpf see man bpfc tcpdump C style format: example: tcpdump high level compiler: $ tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -dd > filter.bpf see man pcap-filter example: bpfc low level compiler: $ bpfc -f C -i filter.asm > filter.bpf see man bpfc

there are several ways to build a BPF:
hcxdumptool's build in high level language compiler
tcpdump's build in high level language compiler
bpfc low level language compiler

To build a BPF, it is mandatory to understand 802.11 protocol (mac frame addr1, addr2 and addr3):
https://en.wikipedia.org/wiki/802.11_Frame_Types
Reply
#74
Thanks a lot devs 🙇
Reply
#75
This AP will be attacked
Code:
bpfc="wlan addr3 112233445566" > attack.bpf

This AP will be protected
Code:
bpfc="not wlan addr3 112233445566" > protect.bpf

This is only basic example.
Reply
#76
The filter technique is similar (the same) to tshark, Wireshark, dumpcap or tcpdump.
That applies to the dump file format (pcapng) too.
Reply
#77
hi devs, I am now in the command

hcxdumptool -i INTERFACENAME -w dumpfile.pcapng -F --rds=1

and it shows my network, I have no idea how to attack my network, what should I do next? Also, after I stopped the above command, I tried the command

tshark -i <interface> -w allframes.pcapng

I changed <interface> to <wlan0>, but it says an error of

Running as user "root" and group "root". This could be dangerous.
Capturing on 'wlan0'
tshark: The file to which the capture would be saved ("allframes.pcapng") could not be opened: Permission denied.

edit, I just exit root mode, and tshark now works
Reply
#78
To attack your network, it is mandatory to build a BPF.
First get the MAC address of your AP. This can be done by
Code:
$ hcxdumptool --rcascan=active


build the filter:
Code:
$ hcxdumptool --bpfc="wlan addr3 112233445566 or wlan addr3 ffffffffffff" > attack.bpfc

do the attack:
Code:
$ hcxdumptool -i INTERFACENAME -w dumpfile.pcapng -F --rds=1 --bpf=attack.bpfc

If the AP does PMKID caching or if a CLIENT is connected to the AP, the attack should be successful in a couple of seconds.
e.g.: attack using an ALFA AWSU035ACM took 0m8,334s:
https://github.com/ZerBea/hcxdumptool/di...nt-7550759

e.g.: attack using an ALFA AWSU035ACHM took 0m7,512s:
https://github.com/ZerBea/hcxdumptool/di...nt-7553512

BTW:
There is no need to run tshark as super user and it is not recommended to do so. But if you run it as super user, a normal user can't open the dump file.
Reply
#79
I forgot to mention:
Don't count on it that you are able to decrypt the entire traffic recorded by tshark during an attack.
Therefore you need a session key that belongs to the same session as the encrypted traffic.
If you miss the begin of such a sequence (e.g. hcxdumptool does channel hopping) the decryption will fail (epically).
Reply
#80
Hi devs, I tried the command

$ hcxdumptool --bpfc="wlan addr3 112233445566 or wlan addr3 ffffffffffff" > attack.bpfc

i changed wlan to wlan0 because it dont work first and mac to the mac visible when rcascan, when I hit enter it says

unrecognized option '--bpfc=wlan0 addr3 a87484c8d49a'

edit: so I successfully run the command by adding space at -- bpfc
Reply