Ubiquity SR71e and Aircrack-NG

Posted by Trevelyn on Tuesday Mar 16, 2010 Under Computer Security, Hacking / Phreaking, WiFi

Well, the card came today. The SR71e from Ubiquity with the Atheros AR9280 chip.

Sadly, the WeakNet Linux Kernel is too old and the ath9k will not inject. In fact, as soon as you inject the first packet, the kernel panics and causes the whole system to lock up and make the Lock keys blink. I remember reading somewhere that certain kernels actually blocked packet inject, this could very well be the case. I plan on using the bleeding edge next time I release a WNLA anyways! But it still works and sniffs fine and goes into monitor mode and managed works fine as well.

The BT4 final disk works with injection though! They used a newer kernel than I, and Here are some shots of the SR71e in action. It was all done within closed boundaries. The aireplay-ng command to fake associate and authenticate was blazing fast. I was deauthenticated though, so adding the appropriate flags to aireplay-ng, like -q 10 would have fixed that but, I just kept bashing away until I got it. i was so close to the router that it really didn’t matter.

Here is a fake authentication with the router. This would have failed instantly if packet injection where not possible with ath9k and this device.



Here are three different atheros based cards. The first on the far left is the AR5BXB6 internal mini PCI Express card. The middle card is the SR71e. The card on the far right is the SMC Networks SMCWCB-G2 PCMCIA card. The hugest difference so far are the client lists!



Since the WEP key I chose is completely numeric I didn’t need that many IV’s, I simply daydreamed a bit too long!



Well, after walking home while creating a WardriveSQL DB entry, the first thing I did was set up a router in my temporary apartment and cracked WEP with it. The clients list is one that the other two cards never see! This is very good for applications like Catchme-NG! where client lists are the payload, and wireless sensitivity counts!

Specifiactions


Here is the output from lspci -vvv for it:


0c:00.0 Network controller: Atheros Communications Inc. AR928X Wireless Network Adapter (PCI-Express) (rev 01)
Subsystem: Device 0777:4e05
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR+ FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- SERR- Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 17
Region 0: Memory at ecef0000 (64-bit, non-prefetchable) [size=64K]
Capabilities: [40] Power Management version 2
Flags: PMEClk- DSI- D1+ D2- AuxCurrent=375mA PME(D0+,D1+,D2-,D3hot+,D3cold-)
Status: D0 PME-Enable- DSel=0 DScale=0 PME-
Capabilities: [50] Message Signalled Interrupts: Mask- 64bit- Queue=0/0 Enable-
Address: 00000000 Data: 0000
Capabilities: [60] Express (v1) Legacy Endpoint, MSI 00
DevCap: MaxPayload 128 bytes, PhantFunc 0, Latency L0s <512ns, L1 <64us
ExtTag- AttnBtn- AttnInd- PwrInd- RBE- FLReset-
DevCtl: Report errors: Correctable- Non-Fatal- Fatal- Unsupported-
RlxdOrd+ ExtTag- PhantFunc- AuxPwr- NoSnoop-
MaxPayload 128 bytes, MaxReadReq 512 bytes
DevSta: CorrErr- UncorrErr- FatalErr- UnsuppReq- AuxPwr- TransPend-
LnkCap: Port #0, Speed 2.5GT/s, Width x1, ASPM unknown, Latency L0 <512ns, L1 <64us
ClockPM- Suprise- LLActRep- BwNot-
LnkCtl: ASPM L1 Enabled; RCB 128 bytes Disabled- Retrain- CommClk+
ExtSynch- ClockPM- AutWidDis- BWInt- AutBWInt-
LnkSta: Speed 2.5GT/s, Width x1, TrErr- Train- SlotClk+ DLActive- BWMgmt- ABWMgmt-
Capabilities: [90] MSI-X: Enable- Mask- TabSize=1
Vector table: BAR=0 offset=00000000
PBA: BAR=0 offset=00000000
Capabilities: [100] Advanced Error Reporting
Capabilities: [140] Virtual Channel
Capabilities: [160] Device Serial Number 00-00-00-00-00-00-00-00
Kernel driver in use: ath9k
Kernel modules: ath9k

Verdict


Ath9k Needs a newer kernel to inject. Aircrack-ng’s website claims “Starting with 2.6.29.4+ and 2.6.28.10+” but WNLAv3 is 2.6.28.14! Even still, it’s an amazing card for the price $59 USD. I would highly recommend it over any other Mini PCI Express card I have ever owned.

Tags : | add comments

WiFu Laptop Modification and ZeroDayExile.com

Posted by Trevelyn on Wednesday Mar 10, 2010 Under Computer Security, Hacking / Phreaking, WiFi

ZeroDayExile.com is back! Nice sleek looking security forums from Tully. Come join us to learn cool tricks and computer security techniques, contribute code, and teach us something new too!

After our latest Taming the Electron show, I was completely inspired by Fixer to modify my laptop. It’s a DELL D620 with many wireless cards in and out of it. I purchased 2 wireless antennas from WiFiLink The DELUXE245-5PLUS This seem very simple, but did in fact boost my range (for RX at least) by almost 3 times. Here is an image I took of the two cards with and without the antennas so you can clearly see the difference.

They were only 14 dollars USD and shipped really fast (2 days total from ordering) right from Texas. Thanks for the tip Fixer!

I drilled 2 tiny holes in the top case and routed the tiny antenna cables right down into the LCD panel case and right past the hinges into the chassis of the laptop. There was a fair amount of of antenna cable which made the job easier. My next modification/upgrade will be to get the SR71e Mini PCIe card from Ubiquity. This will increase the RX / TX extremely as the mW power goes up. The only downfall will be that it will consume a bit more power from the laptops battery. I currently have 2 mini PCIe slots in the d620 that I can easily use for 2 SR71e cards.

The SR71e has an Atheros AR9280 chip, which runs off of the Ath9k driver (which I built right into WNLA3). The kernel I used for the live disk is new enough to support packet injection too, according to Aircrack-ng.org. With a higher powered card, we are excited to see the injection rates and ranges in the lab!

Oh, and the antenna’s fold downwards too, so you can put it back into your bag:

Tags : | 3 comments

Taming The Electron Episode 3 – WiFi Hacking.

Posted by Trevelyn on Saturday Feb 27, 2010 Under Uncategorized

This episode features 2 guests that use Wireless on a daily basis in their profession, Fixer and Tully. It contains tons of great information from Fixer who is very professional, knows his stuff, and is willing to teach us. That is a perfect example of what we would want WeakNet Labs to be; willing to teach. If you are a beginner to wardriving, wifu, wifi hacking, etc, -> This show is for you!
The episode will be aired Sunday Feburary 28th on Cacti Radio cactiradio.com So join us on Sunday!

~Douglas.

Tags : | add comments

Finally, the paper I have been talking about is done! http://weaknetlabs.com/multimedia/papers/android.pdf I followed it all the way through and it all works fine, as long as you have Eclipse installed already. Installing it and setting it up with WeakNet Linux for Android Development is actually quite simple and will be yet another tutorial for the future.  Once you have this installed, making applications for Android is very simple – finding good documentation for hasty people who don’t know Java – is hard.  This paper mashes all of those considerations into a heap of easy to follow directions to get you coding apps that play sounds, change layouts when screen layout is changed, show images, make buttons, make image buttons, backgrounds and more!  You don’t need to know Java! :D

I wrote this document out of my Hotel room, so of it seems a bit weak, please feel free to Email me.  WeakNetLabs [at] Gmail [dot] com OR Douglas [at] WeakNetLabs [dot] com

Taming the Electron Episode 3 is in the works!  Yes, this episode will be about Wireless hacking, our recent android work, and more Drum and Bass music.  Stay posted for more news as the show progress moves on.  We apologize for the HUGE delay, but due to acts of nature on the Lab, we have been forced to stop for a while.  Thanks again to all who have commented with us and left us E-Love – We E-Love you back!

Thanks again for stopping by, we will have more news soon!

Tags : | add comments

Soldering and Hardware Hacking

Posted by Trevelyn on Thursday Feb 18, 2010 Under Uncategorized

Yesterday, WNL made this:

It’s an Atari Punk Console project from MAKE Magazine, which I actually bought from HackPGH: MAKE Magazine APC and was a great way to learn about soldering and fitting the electronics into a project case. After the Lab was destroyed I had to replace a lot of electronic solid state components, tools, and more that were in a tool case that I started collecting to start making Hardware for WNL. I even had an Arduino that I was writing small code for (which I have yet to replace). So expect to see more cool hardware coming out from us.

Life in the Hotel: sucks. It was nice for a while, but now the Pool is broken and I get really bored at night. It will still be a long time before the Lab is reconstructed, soon I will post pics. The scent of smoke is still so strong on the third floor that sometimes when I walk up there to inventory things or what have you, I get spooked like the place is still on fire!

The Android Whitepaper is done, and I will be uploading it soon, I am still making some finishing touches. I followed along with it all the way through after I wrote it to make sure it all works and that I didn’t leave anything out, so expect to see that soon!

Thanks again for all your E-Love! thanks steenkypeet, Tully, Steve, CypheR, P3nt3st, RBCP, Altalp, and OKCgeek. Thanks to everyone who sent E-Love!

~Douglas.

Tags : | 6 comments

Phone Losers of America Red Box Android App!

Posted by Trevelyn on Wednesday Feb 10, 2010 Under Uncategorized

Yeah, this on is now in the market as well. All of these apps are still in BETA stages and I am a newb at Java, so be easy on the comments, please?
I will posting a good information and easy to follow tutorial on my web blog (www.trevelyn.com)coming soon, so be sure to follow our RSS feeds!! Thanks!

Tags : | add comments

Phone Losers of America app for Android!

Posted by Trevelyn on Wednesday Feb 10, 2010 Under Uncategorized

Yup! It’s a simple Blue Box app.  It’s free, so just dl it in the Android Market.  I also have a Red Box application coming soon too and will post back once it is released.  Have fun.  Original post: http://www.phonelosers.com/index.php?topic=4716.0

Please rate it if you download it! :)

Tags : | 4 comments

Taming The Electron Android App

Posted by Trevelyn on Saturday Feb 6, 2010 Under Uncategorized

I uploaded our first Android app and left a few sneak peeks of Catchme-NG! for Android on the Catchme-NG! web page.

It simply plays the stream for the current episode of Taming The Electron from our web server. Please download it and check it out and rate it! It’s free!
Despite what has happened to the Lab recently, I will be creating a new episode for TtE for next Sunday.

This is my first attempt at coding in Java for Android. Before this, I never touched Java and I plan on not doing it much after! I have a few more apps I will be releasing into the Android Market including apps for PLA (PhoneLosers of America) almost identical to those I released on the Nintendo DSi.

I apologize for charging $1 USD for Catchme-NG!, this is simply to help me rebuild what was destroyed by the fire, as from what my insurance company says seems pretty bleak.

Thank you all for your comments and support over the last 2 weeks, i greatly appreciate the support!

~Trevelyn.

Tags : | 8 comments

WeakNet Labs destroyed by fire.

Posted by Trevelyn on Sunday Jan 31, 2010 Under Updates

At around 6:45am on Thursday January 28th, I was aroused by my girlfriend who smelled smoke. I ran into the lab and saw the ceiling fan was missing and the ceiling had a large hole with flames in it. The room above had an electrical fault with set the whole room on fire. Firemen put the fire out, but the lab (my home) was destroyed. Insurance says it will be months before I can move back in and that most of the units in the server rack were not covered as they had a “data processing” limit of $1,500. Sadly, we were just about to release software for Google Android and we were head on in our new show Taming the Electron. I apologize to those who actually relied on our servers for shells and storage. We have suffered a huge loss, even though we made it out of the emergency alive. I buried three pets 2 days ago. WeakNet was my life, my life’s work and my proudest investment. To stand in the snow and watch things get destroyed by fire and water was something that will probably haunt me forever.
This can only make us stronger and we will not stop releasing media and software. Please stay posted and watch our RSS feeds, even if we have long delays. Thank you all.

~Trevelyn

Tags : | 8 comments

Live!

Posted by Trevelyn on Thursday Jan 21, 2010 Under Updates

We are now live! Bask in the glory of our new, sleek looking website! If anyone finds any bad links, please feel free to let us know. Thank you for coming!

Tags : | 4 comments