Plugins 2500/2501 and 16800/16801 are deprecated
#81
If the internal BPF compiler is available depend on how hcxdumptool has been compiled (see Makefile).
My version (development system running Arch Linux) is compiled with BPF compiler:
Code:
$ hcxdumptool -v hcxdumptool 6.3.2-70-gdf8f2e6 (C) 2023 ZeroBeat running on Linux kernel 6.6.3-arch1-1 running GNU libc version 2.38 compiled by gcc 13.2.1 compiled with Linux API headers 6.4.0 compiled with GNU libc headers 2.38 enabled REALTIME DISPLAY enabled GPS support enabled BPF compiler
If the internal BPF compiler is disabled, you have to use a third party tool (e.g. tcpdump) to build a filter.
Reply
#82
this is what shows on my end

─$ hcxdumptool --version                                      
hcxdumptool 6.3.2-70-gdf8f2e6 (C) 2023 ZeroBeat
running on Linux kernel 6.5.0-kali3-amd64
running GNU libc version 2.37
compiled by gcc 13.2.0
compiled with Linux API headers 6.5.6
compiled with GNU libc headers 2.37
enabled REALTIME DISPLAY
enabled GPS support
disabled BPF compiler
Reply
#83
I tried creating a filter with the help of hcxdumptool --help

tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -ddd > filter.bpf

I only changed 112233445566 to my mac address then hit enter

then still BPC is unset
Reply
#84
What happens after hcxdumptool has been started:

it requests the regulatory domain settings (to figure out what is allowed)
it requests the the capabilities of the attack device
it sets monitor mode (active monitor mode if possible)
it sets lowest bit rate and smallest bandwidth (to increase range)
it scans for the target(s)

upper display:
if a target is in range an under attack a + appears in the R column
it requests the PMKID from the target - a + appears in the 1 column
if the target support PMKID caching a + P appears in the P column
it reconnects to the target connected CLIENTs (if that fails tries to disconnect them)
if it got a 4way handshake a + appears in the 3 column
a plus in the S column show that the AP uses a WPA-PSK mode

lower display:
if the CLIENT respond to an EAP request, a + appears in the E column
if the CLIENT connects to hcxdumptool a + appears in the 2 column

If you got a plus in the P, 3 or 2 column you can stop hcxdumptool and convert the pcapng file to hashcat's hc22000 format.
Either you can use hashcat's online converter (that runs hcxpcapngtool):
https://hashcat.net/cap2hashcat/

or you can use hcpcapngtool
https://github.com/ZerBea/hcxtools
Code:
$ hcxpcapngtool -o test.hc22000 dumpfile.pcang

Now you can start your offline attacks running hashcat's different attack modes as described here:
https://hashcat.net/wiki/

e.g. word list attack:
Code:
$ hascat -m 22000 test.hc22000 wordlist
If the PSK is inside the word list, hashcat will show it.

An up to date word list (c-nets) is here:
https://wpa-sec.stanev.org/?dicts
or here
https://hashmob.net/resources/hashmob
Reply
#85
(12-05-2023, 12:55 PM)yuXfar Wrote: I tried creating a filter with the help of hcxdumptool --help

tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -ddd > filter.bpf

I only changed 112233445566 to my mac address then hit enter

then still BPC is unset

Something is wrong with your work flow. Please check the command lines.
Added cat filter.bpf to see that has been really compiled.
Code:
$ tcpdump -s 65535 -y IEEE802_11_RADIO wlan addr3 112233445566 -ddd > filter.bpf $ cat filter.bpf $ hcxdumptool -i INTERFACE --bpf=filter.bpf -F -rds=1
Reply
#86
Linux does not forgive mistakes/typos on the command line level.
Reply
#87
when converting dumpfile, i get this information warning

frequency statistics from radiotap header (frequency: received packets)
-----------------------------------------------------------------------
not available due to missing radiotap header

Information: no hashes written to hash files

Information: missing frames!
This dump file does not contain BEACON or PROBERESPONSE frames.
This frames contain the ESSID which is mandatory to calculate a PMK.
It always happens if the capture file was cleaned or
it could happen if filter options are used during capturing.
That makes it impossible to recover the PSK.

Information: missing frames!
This dump file does not contain undirected proberequest frames.
An undirected proberequest may contain information about the PSK.
It always happens if the capture file was cleaned or
it could happen if filter options are used during capturing.
That makes it hard to recover the PSK.

Information: missing frames!
This dump file does not contain important frames like
authentication, association or reassociation.
It always happens if the capture file was cleaned or
it could happen if filter options are used during capturing.
That makes it hard to recover the PSK.

Information: missing frames!
This dump file does not contain enough EAPOL M1 frames.
It always happens if the capture file was cleaned or
it could happen if filter options are used during capturing.
That makes it impossible to calculate nonce-error-correction values.


session summary
---------------
processed pcapng files................: 1
Reply
#88
Nothing has been captured and your dump file is empty.
How determine a PMKID or a 4way handshake has been captured is described here:
https://hashcat.net/forum/thread-10253-p...l#pid59679

If you are not sure how to read the display information add --exitoneapol=7 to your command line.
hcxdumptool will terminate after a PMKID/handshake has benn captured.


BTW:
This warning is always displayed if undirected PROBEREQUESTs are filtered out by BPF:
Code:
Information: missing frames! This dump file does not contain undirected proberequest frames. An undirected proberequest may contain information about the PSK. It always happens if the capture file was cleaned or it could happen if filter options are used during capturing. That makes it hard to recover the PSK.
Reply
#89
I haven't used any filter during this scan, I followed your instructions, how to fix this?
Reply
#90
Please comment output of hcxdumptool -L. There are some drivers/devices that do not support hcxdumptool's attack modes.
Reply