Before you start hcxdumptool make sure that all services that take access to the device are stopped (as mentioned in --help).
|
Plugins 2500/2501 and 16800/16801 are deprecated
|
|
12-04-2023, 03:32 PM
Thank you so much devs. I have run the commands needed and I noticed there is a line saying
BPF is unset! ... How can I enable this? Thank you
hcxdumptool use the Berkeley Packet Filter (BPF) to select a target or to protect own devices. Its entire attack behavior can be controlled via this BPF.
If the filter is not applied, hcxdumptool will attack everything in range merciless. You'll see this warning: Code: BPF is unset! Make sure hcxdumptool is running in a 100% controlled environment!A (very) simple BPF code is explained in -h): Code: --bpfc=<filter>: compile Berkeley Packet Filter (BPF) and exit
$ hcxdumptool --bpfc="wlan addr3 112233445566" > filter.bpf
see man pcap-filter
--bpf=<file> : input Berkeley Packet Filter (BPF) code (maximum 4096 instructions) in tcpdump decimal numbers format
see --help for more informationCode: Berkeley Packet Filter:
-----------------------
tcpdump decimal numper format:
example: tcpdump high level compiler:
$ tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -ddd > filter.bpf
see man pcap-filter
example: bpf_asm low level compiler
$ bpf_asm filter.asm | tr ',' '\n' > filter.bpf
see https://www.kernel.org/doc/html/latest/networking/filter.html
example: bpfc low level compiler:
$ bpfc -f tcpdump -i filter.asm > filter.bpf
see man bpfc
tcpdump C style format:
example: tcpdump high level compiler:
$ tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -dd > filter.bpf
see man pcap-filter
example: bpfc low level compiler:
$ bpfc -f C -i filter.asm > filter.bpf
see man bpfcthere are several ways to build a BPF: hcxdumptool's build in high level language compiler tcpdump's build in high level language compiler bpfc low level language compiler To build a BPF, it is mandatory to understand 802.11 protocol (mac frame addr1, addr2 and addr3): https://en.wikipedia.org/wiki/802.11_Frame_Types
12-04-2023, 03:54 PM
Thanks a lot devs 🙇
12-04-2023, 03:58 PM
This AP will be attacked
Code: bpfc="wlan addr3 112233445566" > attack.bpfThis AP will be protected Code: bpfc="not wlan addr3 112233445566" > protect.bpfThis is only basic example.
The filter technique is similar (the same) to tshark, Wireshark, dumpcap or tcpdump.
That applies to the dump file format (pcapng) too.
hi devs, I am now in the command
hcxdumptool -i INTERFACENAME -w dumpfile.pcapng -F --rds=1 and it shows my network, I have no idea how to attack my network, what should I do next? Also, after I stopped the above command, I tried the command tshark -i <interface> -w allframes.pcapng I changed <interface> to <wlan0>, but it says an error of Running as user "root" and group "root". This could be dangerous. Capturing on 'wlan0' tshark: The file to which the capture would be saved ("allframes.pcapng") could not be opened: Permission denied. edit, I just exit root mode, and tshark now works
12-05-2023, 11:38 AM
To attack your network, it is mandatory to build a BPF.
First get the MAC address of your AP. This can be done by Code: $ hcxdumptool --rcascan=activebuild the filter: Code: $ hcxdumptool --bpfc="wlan addr3 112233445566 or wlan addr3 ffffffffffff" > attack.bpfcdo the attack: Code: $ hcxdumptool -i INTERFACENAME -w dumpfile.pcapng -F --rds=1 --bpf=attack.bpfcIf the AP does PMKID caching or if a CLIENT is connected to the AP, the attack should be successful in a couple of seconds. e.g.: attack using an ALFA AWSU035ACM took 0m8,334s: https://github.com/ZerBea/hcxdumptool/di...nt-7550759 e.g.: attack using an ALFA AWSU035ACHM took 0m7,512s: https://github.com/ZerBea/hcxdumptool/di...nt-7553512 BTW: There is no need to run tshark as super user and it is not recommended to do so. But if you run it as super user, a normal user can't open the dump file.
12-05-2023, 11:44 AM
I forgot to mention:
Don't count on it that you are able to decrypt the entire traffic recorded by tshark during an attack. Therefore you need a session key that belongs to the same session as the encrypted traffic. If you miss the begin of such a sequence (e.g. hcxdumptool does channel hopping) the decryption will fail (epically).
Hi devs, I tried the command
$ hcxdumptool --bpfc="wlan addr3 112233445566 or wlan addr3 ffffffffffff" > attack.bpfc i changed wlan to wlan0 because it dont work first and mac to the mac visible when rcascan, when I hit enter it says unrecognized option '--bpfc=wlan0 addr3 a87484c8d49a' edit: so I successfully run the command by adding space at -- bpfc |
|
« Next Oldest | Next Newest »
|
