PaulDotCom mailing list archives

Re: Karmetasploit with Airbase-ng


From: Robert Portvliet <robert.portvliet () gmail com>
Date: Mon, 19 Jul 2010 09:31:12 -0400

Crap, was going to suggest 1800... I'll do some more digging later..



On Mon, Jul 19, 2010 at 9:28 AM, Carlos Perez <carlos_perez () darkoperator com
wrote:

the VM is in Fusion running BT4 on an OSX box with the USB wireless card in
passthru to the VM. MTU on that one is 1400 I tried also 1500 and 1800

On Jul 19, 2010, at 6:35 AM, Robert Portvliet wrote:


Hey, is this about the same thing you're seeing?


http://docs.freebsd.org/cgi/getmsg.cgi?fetch=957467+0+archive/2009/freebsd-bugs/20090322.freebsd-bugs

I'm seeing a bunch of the same kind of packets:

08:45:23.956836 00:17:f2:99:d7:cf Null > ff:ff:ff:ff:ff:ff Unknown DSAP
0x08 Supervisory, Receiver not Ready, rcv seq 0, Flags [Command], length 98

and

08:45:47.765489 00:17:f2:99:d7:cf Unknown SSAP 0xdc > 33:33:00:00:00:fb
Unknown DSAP 0x86 Information, send seq 48, rcv seq 0, Flags [Response],
length 220

Are you running Karmetasploit on a Linux host or a Linux guest on a OSX
host & bridging?

Also, what is your MTU set to?





On Sun, Jul 18, 2010 at 2:03 PM, Carlos Perez <
carlos_perez () darkoperator com> wrote:

BT4 latest patches and latest kernel with card Alfa AWS036EH and a Cisco
AIR-CB21AG-A-K9

Linux bt 2.6.34 #1 SMP Thu Jul 8 19:41:21 EDT 2010 i686




On Jul 18, 2010, at 1:39 PM, Robert Portvliet wrote:

A couple questions..

Malformed how?

Is this on Linux or Windows? (Linux,I assume..)

Can you provide a packet capture?



Cheers,

Rob


On Sun, Jul 18, 2010 at 10:48 AM, Carlos Perez <
carlos_perez () darkoperator com> wrote:

Hi guys

Has anybody been having problems setting a Fake Karma type AP  using
Airbase-ng? for some reason the packets in that network look malformed, this
is the reason that dhcpd is not working properly, I have played with the MTU
size several times and nothing. Any help is more than welcomed.

Thanks,
Carlos
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




--






_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




--

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




-- 
Robert Portvliet
GIAC GPEN, GCIA, Security +
http://twitter.com/rportvliet
http://invokingthedaemon.blogspot.com/
http://www.linkedin.com/pub/robert-portvliet/10/A34/689
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

Current thread: